By Ray Birch
ST. PETERSBURG, Fla.—All of the media attention given to the Equifax breach may lead credit unions to “overreact” and create “crime scene investigations” around card business, asserts one expert, who is suggesting several steps to more effectively address the breach.
Jack Lynch, SVP and chief risk officer for PSCU, is concerned that member reaction to media coverage of the breach—which involves as many as 145 million credit files—may lead to credit unions taking unnecessary and possibly drastic actions in response.
“Because of what you are hearing on the news and Congress getting involved you would think we have another Home Depot breach on our hands and have to reissue millions of cards,” Lynch told CUToday.info. “With all that noise, there is the potential of reacting and not understanding the extent of the problem and what to do. We have credit unions asking us if they should lock down their card accounts, and we are saying no.”
Lynch emphasized that PSCU is not downplaying the seriousness of the breach, but added comparing the Equifax breach to the 2014 Home Depot incident is a mistake. He emphasized that the two breaches are “two different animals” and that the resulting fraud will be different.
Another Home Depot Moment?
With Home Depot the issue was the significant number of card numbers exposed that required quick action to protect members’ plastic. But with the Equifax breach, the big problem will eventually be account takeover fraud, emphasized Lynch.
“At this point, from the evidence we have and what we are seeing, credit unions need to take more of a balanced approach to combatting this attack,” said Lynch. “You don’t want to negatively affect the member card experience by closing down accounts and reissuing or starting to do a bunch of transaction declines. Your card will get moved to the bottom of the wallet when there is not yet evidence that fraudsters are exploiting cards from this.”
Instead, Lynch recommended credit unions carefully monitor transactions and stay as informed as possible on potential fraudster use of the Equifax data.
“I do believe credit unions should be relying on sources—trusted partners, trusted media—to stay informed on the latest news regarding the Equifax breach,” said Lynch. “Communication should be the focus now, and making sure defenses are shored up and monitoring fraud strategies, monitoring what is coming into call centers. That is the key right now, as opposed to overreacting.”
As other experts have told CUToday.info, the big threat from the Equifax hack is likely coming down the road, when crooks either perform account takeovers or create synthetic IDs and open new accounts to steal funds.
As credit unions begin to watch transactions more closely, Lynch cautioned them not to dig too deep unnecessarily.
“You don’t want to turn your new account openings, new memberships, and other transactions into crime scene investigations,” Lynch said. “You will be turning away good members and good business. So instead of overreacting you could instead begin, in the example of a new account, relying on more than credit bureau information and seek other forms for validation from third parties.”
Communication Key
Lynch also emphasized that members should be communicated to regularly about how the credit union is stepping up its vigilance in the wake of the Equifax breach, and also providing members with contact information at Equifax.
“You need to have messaging around members’ accounts being safe and secure and that the credit union is closely monitoring accounts in the event a fraudster takes action,” he said.
Lynch said PSCU’s call center is adding new fraud detection strategies to specifically address the Equifax breach. While it is not stepping up declines, the company is monitoring more closely for suspicious activity.
“We have, as well, put together talk tracks for our call center team regarding the Equifax breach,” he said.
Throughout his discussion with CUToday.info, Lynch stressed the Equifax breach certainly demands a strong reaction from credit unions. “This is about staying informed, focusing on new threats, communicating to members—a lot of due diligence.”
