Pub. 8 2019 Issue 3

May/June 2019 19 l e a d i n g a d v o c a t e f o r t h e b a n k i n g i n d u s t r y i n k a n s a s A s the use and sophistication of technology increases, it would stand to reason that it would be more difficult for fraudsters to gain access to bank accounts via ATMs. Unfortunately, crooks seem to be equally sophisticated, and quickly outwit many safeguards soon after they are put in place. Here are some highlights and examples of ATM frauds that are unfolding across the country Confirm That Your ATMs Are EMV Chip Enabled A particular type of ATM fraud is showing up in many areas. It involves the use of foreign counterfeit cards being used at ATMs. While the cards used in the fraud have EMV chips, the ATMs that have been attacked were not EMV chip enabled. The fraudsters find the institutions without the EMV enabled ATMs, empty the cash with fraudulent transactions, and then drive to the next branch location (assuming that more of that particular bank’s ATMs are not EMV enabled). The lack of EMV hardware shifts the financial liability for the fraud back to the bank that owns the ATM. Confirm that your ATMs are EMV chip enabled. If not, you should consider restricting access of any cards that aren’t issued by your bank, and call your ATM vendor to get the EMV hardware and software installed immediately. Cardless ATM Transactions While they sound convenient, cardless ATM transactions are now the newest target of fraud. Fake Text Scam: Customers can receive text messages “from the bank” that send them to a fake link. The customer is told that their account has been locked and they need to provide personal information. This information is then used to initiate and complete cardless ATM transactions. Cloned Phone Scam: Many of these scams are originating while a customer is using unsecure public Wi-Fi. The fraudsters are able to gain login and account information as well as phone information. They use the information to clone the customer’s phone or add a new number to the account to initiate transfers. ATM Security Suggestions • Confirm that your ATMs are EMV chip enabled. • Educate customers to use mobile banking apps on either their cellular network, or on a secure Wi-Fi network. • Remind customers that the bank does not send “unsolicited” emails or texts. • Limit cardless ATM withdrawals to a small dollar amount and limit daily usage. • Limit the timeframe that a transaction code is viable. • As it becomes available, utilize biometric identification (fingerprints, iris and facial recognition). • Maintain usage of multi-factor authentication methods. About OneBeacon Financial Services OneBeacon Financial Services offers property and casualty coverages for commercial banks, savings banks and savings and loan institutions, security broker- dealers, investment advisors, insurance companies and credit unions. Specialty coverages, including professional liability, trust errors & omissions, cyber liability and financial institution bond are additionally available for institutions with less than $3 billion in assets. Contact Us To learn more about how OneBeacon Financial Services can help you manage your unique risks, please contact Craig M. Collins, President, at ccollins@onebeacon.com or 952.852.2434. THIS YEAR’S CONFERENCE WILL BE THE PLACE TO MAP OUT YOUR STRATEGY FOR SUCCESS . Educational Resources 785.232.3444 www.ksbankers.com Past attendees had this to say: “Overall great conference covering a variety of issues that I deal with on a day to day basis. ” “Great Conference. One of the best I have attended.” Why Should I Attend?  You May be Playing in the Minors, But Act Like a Major League Player  The National and Local Economies and Their Impact on You  Capturing UFOs: Unapparelled Funding Opportunities  Social Engineering: Solving the Problem of People  To Catch a Spy: The Art of Counterintelligence  Sessions on: CECL, Loan Structure, Regulatory Hot Topics, Banking Cannabis in Kansas, and Participation Loans  Communicate More Effectively with Your Boss, Your Staff and Your Customers By Craig M. Collins, President, Financial Services, OneBeacon NEWS FROM THE VAULT ATM FRAUD ALERT

RkJQdWJsaXNoZXIy OTM0Njg2