Showing posts with label chargebacks. Show all posts
Showing posts with label chargebacks. Show all posts

Friday, October 05, 2007

Retailers call for a level playing field on data security

The data breach at TJX, which compromised approximately 45 million people has spawned a looming battle between retailers and the financial industry. At stake is who will bear the future costs of data breaches, which are becoming more expensive than ever before.

Thus far, we've seen legislation introduced to hold retailers responsible and calls for PCI data security standards. Legislation has been passed in Minnesota and is awaiting Governor Schwarzenegger's signature in California.

In any disagreement, there are two sides to a story -- and now the National Retail Federation (NRF) is bringing up what I consider is a valid point -- which is if they weren't required to store all this information, it would be harder to steal.

Under current rules, they are required to maintain too much information for 18 months, or face what are known as chargebacks.

Chargebacks are when a customer requests a refund from their card issuer, normally because of fraud. Please note that some dishonest customers claim fraud, when it never occurred. Additionally, the payment card industry sets the due diligence standards when accepting their cards and actively promotes their use.

The bottom line is -- merchants can accept payments, follow all the rules, and if they can't provide the required information -- they get charged for it, anyway.

With all the fraud that results from payment cards, this could get pretty expensive for a retailer, if they fail to control it.

Saying all this, we need to consider the bigger picture, which is the best way to protect data is to limit how many places it is being stored. This principle should be considered in a lot of other places besides retailers, also.

Mark Jewell of the AP is reporting:
The National Retail Federation on Thursday urged a card industry organization to stop requiring retailers to keep customers' card numbers for up to 18 months.

The stored data helps track product returns and disputed or suspicious transactions. But retailers say the data would be more secure if only credit card companies and banks that issue the cards stored it.

"It makes more sense for credit card companies to protect their data from thieves by keeping it in a relatively few secure locations than to expect millions of merchants scattered across the nation to lock up their data for them," David Hogan, the retail federation's chief information officer, said in a strongly worded letter.
In the article, Mr. Hogan brings up the very reason that retailers have been holding on to what some consider, too much information:

Hogan said in an interview that retailers routinely hold onto information because credit card companies ask them to produce data from transactions as old as 18 months to verify product returns and protect against fraud. If retailers can't produce data showing the product was legitimately purchased, they can end up reimbursing banks and card companies, Hogan said.
Only 44 percent of large retailers are now PCI compliant. This month, the larger retailer's banks will start facing fines for failing to become compliant. Banks that service medium size retailers will start facing fines in January.

This doesn't even take into account smaller merchants, who often are victimized the most by fraud, and chargebacks.

In case you don't understand how chargebacks can be a burden to a merchant, I've included a YouTube video at the bottom of this post, where a small merchant rants about chargebacks from PayPal.

The frustration expressed in this video is the same one felt by a lot of merchants (retailers).

The basic issue in all this is who will end up paying for it. Since no business remains solvent if they are losing money, the costs are going to end up being passed on to the consumer.

So far as the NRF's point, I think it is entirely valid. If retailers didn't have to store all this data, it would be one less place, where criminals could access it.

After all, while data breaches at retailers have gotten a lot of attention recently, they are not the only place they are occurring.

If you are interested in seeing what I mean by this the Privacy Rights Clearinghouse, PogoWasRight and Attrition.org all try to keep track of as many of them as they can.

All of them will tell you that their efforts only document the known breaches. There are probably many more that no one knows about -- and the last I heard -- the criminals behind them keep this a closely guarded secret.

After all, disclosure of a data breach impacts their bottom lines, also.

My personal solution is for everyone to get together and go after the real people behind this problem, or the criminals. Everyone would benefit from this!

My guess is they (the criminals) could care less, who ends up paying for all the damage they are causing.

AP story, here.

National Retail Federation (NRF) press release, here.

Here is the YouTube video (mentioned above), which reflects a small merchant's frustrations with the chargeback process. Please note that smaller merchants are bound to have a stake in what becomes of this controversy, also.

(YouTube video courtesy of Terry)

Thursday, March 22, 2007

SIRAS – Smart technology that protects profit and privacy


Organized retail crime, according to RILA (Retail Industry Leaders Association), is a $34 billion a year problem. A study at the University of Florida conducted by Dr. Richard Hollinger suggests that 9 percent of all refund activity or $16 billion is fraudulent.

At most merchants today, refunds are tracked with personal information. While this was effective 10 years ago, the information in the current databases might not be as accurate as it once was.

Personal and financial information is stolen and sold in a lot of places, most notably over the Internet. A perfect example is the recent compromise of consumer data at TJX stores. This information is turned into fraudulent identification and financial instruments and sold to criminals.

It is likely that criminals can assume multiple identities, using other people’s information to refund merchandise. In fact, payment (credit/debit) card and bad check fraudsters already demonstrate this ability on a daily basis.

With the negative publicity surrounding data breaches and identity theft, honest customers are nervous when asked to surrender their personal details. Recently, privacy groups and Senator Chuck Schumer have been openly critical of current systems, which gather personal information.
A company named SIRAS provides a means to protect an organization’s bottom line and their customer information, also. The way they do it is so simple, it’s brilliant. Instead of tracking personal information, SIRAS tracks the merchandise, itself.

The SIRAS system captures the UPC and serial number of a product at the point-of-sale and creates an electronic receipt. This enables a merchant to determine exactly when and where it was sold AND how it was paid for.

SIRAS can tell when the merchandise was never purchased (stolen), or if it was purchased at another retailer. It also can identify counterfeit merchandise, price switching and altered/counterfeit receipts. Because it ties into a sales transaction, the system could also identify fraudulent forms of payment used to purchase the merchandise, or if the item has been a chargeback issue.

SIRAS makes it pretty hard do a fraudulent refund. Getting series of numbers to match can be extremely difficult, if not almost, impossible.

The data is compiled into customized reporting tools, which can be leveraged to determine risk factors when merchandising products. These tools also have extremely useful applications from an intelligence (analysis) and investigation perspective.

Besides organized retail crime, the largest losses suffered by merchants are caused by internal theft. Fraudulent refunds, “sweetheart returns,” enable dishonest employees to steal cash, or issue credit to payment cards. Like their external counterpart, internal criminals now have to use personal information to prompt a point-of-sale system to issue a refund. Again, this information (which might not be accurate) corrupts a lot of the current databases.

Dishonest employees are going to have a hard time being able to match UPC/serial number to a legitimate sale. This will prevent employees from attempting to commit refund fraud, and should they decide to do so, the custom reporting tools (when used properly) would identify the culprits, with ease.

SIRAS can track and identify retail theft a long way past the refund counter. With its unique ability to track merchandise to a sale, SIRAS can be used to identify merchandise sold in fencing operations (and more likely) via Internet auctions.

In fact, SIRAS has been used to help prove criminal cases, or to obtain search warrants by law enforcement.

The system can also be used to identify counterfeit goods, wherever they might be appear for sale.

Other benefits include being able to better manager warranty programs and in the case of call centers (crucial in e-commerce), it provides their employees with direct access to the original purchase information.

An effective merchandising application, I noted was the ability (via analysis) to identify products that have a high rate of being defect rate, or that aren’t as easy to use, as advertised.

SIRAS has applications that go far beyond fraud at the refund counter.

The system is easily incorporated with patented technology into current point of sale systems and employee training is minimal. Being that it replaces many labor intensive tasks, payroll can be better spent in other areas.

SIRAS applications are beneficial not only to manufacturers and traditional retailers, but the system is equally effective in e-commerce applications.

This technology is already being used by several major retailers and manufacturers. You can view a list of them on their website (listed below).

With privacy becoming a bigger issue all the time, SIRAS provides a smart way to protect assets and not expose customer information. SIRAS makes it harder to commit fraud in a retail environment, while making it easier (customer friendly) to return an item without a paper receipt.

More information about SIRAS and who uses their services can be viewed at:
CNET's story about the TJX data breach can be viewed, here.

Wednesday, January 24, 2007

Small Businesses are often the victims of financial misdeeds

Large businesses often employ dedicated experts to protect their assets. Unfortunately, smaller business can't afford these resources, and therefore are more vulnerable to fraud losses.

And it's easier for these larger businesses to write-off their fraud losses. The sad truth is that - if not managed properly - fraud losses can put a smaller business "out of business."

The Association of Certified Fraud Examiners noted in the 2006 report to the nation that small businesses seem to suffer "disproportionate fraud losses," when compared to larger organizations.

I did a previous post, which links to the report, here.

I read an interesting article by Lena West (CEO of xynoMedia Technology) that offers some practical advice to small businesses.

Ms. West writes:

It is officially open-season on small businesses. Hackers, phishers, spammers and fraudsters often use small businesses as target practice before going after the big guys, though it's news that often doesn't make it in the headlines. No one really knows the true impact of online security breaches, as only 20 percent of businesses reported computer intrusions to legal authorities, according to the FBI and Computer Security Institute. And every online merchant knows the threat of bogus credit card purchases is one that never goes away.
Full story from e-commerceguide.com, here.

The story points on how to deal with and protect yourself from everything from data-breaches to credit/debit card chargebacks.

Since in my opinion (awareness is the best and most effective fraud tool) - this article is great information for anyone, who owns a smaller business.