Learning Lessons From Large Scale Breaches
At this point, there’s no ignoring it: our financial security is compromised daily. And no doubt, many reading this wouldn’t hesitate to recount all the breaches they have been a part of as consumers; merchant breaches in which replacement cards forced you to update your linked accounts, or data compromises where personal information was stolen and identity theft protection was provided, forcing you to consider freezing new credit originations.
These are only the breaches we know about — considering the residual risk of all the data breaches we’ve been exposed to, the totality of it all becomes immense. Back at the start of 2014, I suggested that we’re experiencing data breach fatigue; today it’s closer to data breach exhaustion, and consumers may now feel powerless.
We must ask ourselves as consumers, what exactly is being compromised? What information has fallen into the pocket of an attacker and how could they use it to attack me? As we are compromised once, twice, or multiple times, are we falling under greater risk? How vulnerable are we when it is revealed that personal details landed in the hands of hackers and fraudsters?
Typically, most concerning for consumers is demographic data that can be uses in authentication, illegitimate identity-theft account opening, or the use of a payment card for unauthorized spending (or potentially for account takeover) if an attacker has the relevant non-public personal information. There is a risk here to be sure, even if we, as service providers, don’t realize the impact of it. So what lessons are out there?
Zombie authenticators and static data elements are a gift to hackers
Well, for starters; why are we still using knowledge-based authentication based on third-party-issued static data elements to authenticate? Government (in the U.S. Social Security) identity numbers, home addresses and the user’s date of birth are zombie authenticators – even worse than passwords! They have been compromised so many times, or are sometimes available through public or searchable sources… still in 2017.
Fraudsters have databases to store these elements as well, and anyone who has an account on a dark website can search an underground database to see if a birthday, SSN (social security number) or home address exists for the intended target. In fact, there is already a neologism for this: “Credential Stuffing” – the act of intercepting and using as many authentication elements (e.g. account login or recovery credentials) that have been compromised to attempt to take over an account.
Biometrics and other authentication measures should be embraced
When being asked to authenticate myself, I cringe when I see these types of questions. I’d much prefer to do business with an entity that has a more rigid authentication process and does something far more clever and sophisticated to validate that I am, in fact, me. We now have biometrics if the customer can use them remotely, on a mobile app. We have dynamic account-based questions (only known internally to the service provider and customer), and we have multifactor out-of-band authentication… these can be embraced to perform a far greater authentication experience and reduce the potential for account takeover. Would I feel more secure in a world of high-frequency data breaches when I know my financial institution authenticated me with two factors? Could this actually be faster than the present authentication practices of asking multiple questions, throughout a contact center session? Of course!
I know no one wants to get a letter from their financial institution, or look themselves up on a newly-created security webpage to determine they are exposed after a large breach is revealed, but this is a reality. To sit idly by and continue to authenticate with the most static data elements that are most consistently compromised is a lesson of any breach du jour.
Related Blog Posts
Beyond Borders: Navigating the Challenges of eCommerce Expansion
eCommerce continues to flourish, with impressive growth figures year after year. In 2018, global online sales reached almost $3 trillion, and are expected to hit $4 trillion by the end of 2020.
Despite eCommerce taking an increasing slice of the retail pie (which could now be as high as 15 percent according to recent figures), it is increasingly challenging, with competition and cost pressures creating significant issues for merchants of all sizes.
Payments and Fraud: The Paradox Twins
Digital commerce through web and mobile is where merchants predominantly experience shopper growth today. This has become a hugely important domain for their focus. It offers a means for international growth, new market penetration and a way to engage with shopper-hungry Millennials in their culture. Merchants frequently adopt a Digital-First, eCommerce-First or Mobile-First strategy to ensure full corporate buy-in to this strategy.
Open Payments Systems for Merchants: Don't Close Down Your Options
Remember “Open Systems”?
It was a big industry nom du jour in the 80s and 90s. Every IT system had to be open and therefore flexible and future-proof. Nobody can argue with the logic behind this; making systems easy to integrate with other systems, ensuring vendors could cooperate with one another; creating agility to improve time to market and drive down costs.
Knowing New Customers – And How Shared Data Helps in Fighting Fraud
As the eCommerce industry continues its rapid growth, the lines between physical and digital shopping are becoming increasingly blurred. These changes are creating a number of challenges for merchants, not least around customer visibility and fraud prevention.
Why Non-Functional Requirements Should be a Few of Your Favorite Things
It’s not unusual for me to be questioned by retailers as to why some payment solutions are priced differently or more expensively than others – in fact, it would be unusual not to be asked those questions when dealing daily with procurement and finance teams of major multi-national multi-channel merchants!
Adding a Global Payments Layer for Future Growth
Digitization has changed the payments industry completely and irrevocably. Cash payments are in full retreat, as more people pay digitally – with more than 1.6 billion people now shopping online. The digital customer expects an extremely fast and convenient payment experience, with high security standards, and immediate availability of payments information.
Major League Baseball’s Tampa Bay Rays Tell Cash, “You’re Out!”
As a lifelong baseball fan and former resident of Tampa, Florida, I had the pleasure of spending a summer night or three at Tropicana Field, watching my beloved New York Yankees take on the hometown Tampa Bay Rays. And as a fan of cheap tickets, air conditioning in the Florida summer and plenty of great seats, I always enjoyed the “The Trop” despite its poor reputation.
Let’s Get Phygital: eCommerce Is Coming To A Store Near You
While payments vendors continue to pitch and strategize with a focus on omnichannel, the omnichannel story has already moved on.
Make no mistake – omnichannel remains important and the best vendors have solutions that provide a single cloud payments service capable of delivering a single view of the customer across stores and digital channels. And the best retailers utilize these solutions to deliver efficient cross-channel shopping experiences. Meanwhile, many other retailers get by (though seldom rise to the top) with a siloed approach.
Around The World: Taking Stock of Global eCommerce in 2019
As I head to #NRF2019 in New York City next week, I’m excited to see how some of the biggest retailers and merchants see the industry evolving over the coming year. What trends they think are going to shape 2019, and which of 2018’s buzzwords can be put to bed.
Fraudsters Don’t Wait for Peak, So Neither Should You: 2019 Fraud Strategy Starts Now!
In existence for barely two decades, eCommerce has transformed not only the way we shop, but also how retailers plan and execute their marketing strategies around the peak shopping season. Now that we’re deep into this period, retailers will have prepared for changes in buyer behaviors, relaxed their strategies to be within the limits of manageable review rate, and most important of all, put strategies in place for increased fraud attempts.