Debit cards lag credit cards in EMV migration, putting banks at risk

Three times as many credit cards will be chip-enabled by the end of the year as debit cards

Three times as many credit cards will be chip-enabled by the end of the year as debit cards, making the slower banks bigger targets for cybercriminals.

According to Deborah Baxley, principal for cards and payments at Capgemini Financial Services, an estimated 25 percent of debit cards are expected to be ready -- compared to about 75 percent of credit cards.

The reason is that the U.S. debit card system works differently than anywhere else in the world, she said, and it took longer than expected to come up with specifications.

"The industry had to come up with a solution for the unique requirements of the U.S. debit card system," she said. "And to comply with some recent regulations that were part of the Dodd Frank financial reform act, which requires debit cards to have a choice of routing to different debit networks."

According to Baxley, there are about 30 different debit networks in the country.

The specifications finally came out about a year ago, and banks began issuing new cards.

"We expect them to ramp up quickly," she said.

The advantage to banks is that if, say, the bank has issued a chip card but a merchant hasn't yet upgraded their system to handle these cards, and the card turns out to be fraudulent, then the merchant will be liable for the full amount of the fraud.

Currently, the bank is liable. By migrating to the new chip-based cards before the merchants do, the banks stand to save some money -- at least, until the merchants catch up and the liability shifts back to the bank again.

"The bank can avoid those fraud losses by being faster," she said.

But it's not just about missing out on potential savings, Baxley warned.

As more and more banks send out new, chip-based cards to their customers, criminals will have fewer and fewer targets to go after. The banks that lag behind will then become increasingly more tempting targets.

Once both the bank and the merchant have migrated, thieves with lists of credit card numbers from incidents like the Target data breach will have a harder time using them.

If a criminals takes a stolen credit card number and uses it to create a counterfeit card, then tries to use the card to buy something, a new point-of-sale system would be able to recognize it as a card that was supposed to have a chip in it.

"If it doesn't see a chip, then the transaction would fail," Baxley said. "That's what's supposed to happen."

The chip alone isn't a silver bullet, she added. Merchants should also use tokenization and end-to-end encryption to fully protect the payment information as it travels from the physical payment terminals all the way to the issuers.

Judging by the experience of other countries, once everyone upgrades, the criminals move to the online channel, and to cross-border transactions, she said.

The move to chip-based cards, also known as EMV for Europay Mastercard Visa, is scheduled to happen next month, but the cybercriminals aren't likely to react overnight.

"It's going to be gradual," she said. "It's not like a switch flips on October 1 and the world ends."

Join the CSO newsletter!

Error: Please check your email address.

More about CapgeminiMastercardVisa

Show Comments

Featured Whitepapers

Editor's Recommendations

Solution Centres

Stories by Maria Korolov

Latest Videos

  • 150x50

    CSO Webinar: The Human Factor - Your people are your biggest security weakness

    ​Speakers: David Lacey, Researcher and former CISO Royal Mail David Turner - Global Risk Management Expert Mark Guntrip - Group Manager, Email Protection, Proofpoint

    Play Video

  • 150x50

    CSO Webinar: Current ransomware defences are failing – but machine learning can drive a more proactive solution

    Speakers • Ty Miller, Director, Threat Intelligence • Mark Gregory, Leader, Network Engineering Research Group, RMIT • Jeff Lanza, Retired FBI Agent (USA) • Andy Solterbeck, VP Asia Pacific, Cylance • David Braue, CSO MC/Moderator What to expect: ​Hear from industry experts on the local and global ransomware threat landscape. Explore a new approach to dealing with ransomware using machine-learning techniques and by thinking about the problem in a fundamentally different way. Apply techniques for gathering insight into ransomware behaviour and find out what elements must go into a truly effective ransomware defence. Get a first-hand look at how ransomware actually works in practice, and how machine-learning techniques can pick up on its activities long before your employees do.

    Play Video

  • 150x50

    CSO Webinar: Get real about metadata to avoid a false sense of security

    Speakers: • Anthony Caruana – CSO MC and moderator • Ian Farquhar, Worldwide Virtual Security Team Lead, Gigamon • John Lindsay, Former CTO, iiNet • Skeeve Stevens, Futurist, Future Sumo • David Vaile - Vice chair of APF, Co-Convenor of the Cyberspace Law And Policy Community, UNSW Law Faculty This webinar covers: - A 101 on metadata - what it is and how to use it - Insight into a typical attack, what happens and what we would find when looking into the metadata - How to collect metadata, use this to detect attacks and get greater insight into how you can use this to protect your organisation - Learn how much raw data and metadata to retain and how long for - Get a reality check on how you're using your metadata and if this is enough to secure your organisation

    Play Video

  • 150x50

    CSO Webinar: How banking trojans work and how you can stop them

    CSO Webinar: How banking trojans work and how you can stop them Featuring: • John Baird, Director of Global Technology Production, Deutsche Bank • Samantha Macleod, GM Cyber Security, ME Bank • Sherrod DeGrippo, Director of Emerging Threats, Proofpoint (USA)

    Play Video

  • 150x50

    IDG Live Webinar:The right collaboration strategy will help your business take flight

    Speakers - Mike Harris, Engineering Services Manager, Jetstar - Christopher Johnson, IT Director APAC, 20th Century Fox - Brent Maxwell, Director of Information Systems, THE ICONIC - IDG MC/Moderator Anthony Caruana

    Play Video

More videos

Blog Posts