iStock_000015342966Large_twgCommunity banks across the Bay State doubled down their security efforts over the Christmas shopping season when news broke that big box giant Target had been hacked, exposing more than 40 million customers’ credit and debit card information to potential fraud.

Just a week before Christmas, during the busiest shopping season of the year, journalist Brian Krebs broke the news that cyber thieves had hacked into Target’s databases and stolen 40 million customers’ credit and debit card information between Black Friday and Dec. 15.

“When we found out that morning, I knew it was going to be an interesting day,” said Brian Collins, senior vice president and e-banking and payment services director at Enterprise Bank in Lowell.

Banks’ responses to the data breach have ranged from immediately reissuing all possibly compromised cards to taking a “wait and see” approach.

Collins convened the bank’s department heads and streamlined Enterprise Bank’s responses to anticipated questions into one document so everybody handling concerned customers would be on the same page.

“We wanted to make sure everyone responded to the customer with the same answer,” he said. An employee answering a customer’s concerns on the phone, then, would take down that customer’s card number, send the query to a centralized department, and contact the customer by the end of that day to let them know whether their card may have been compromised in the breach. Those customers who had been affected, or potentially affected, could then come into a branch and receive a new card immediately.

Enterprise Bank also shut down the signature function on potentially compromised cards, so customers could still use their cards without any restrictions on how much they could spend or withdraw from an ATM, but instead of signing for any purchases, they keyed in their PINs.

So far, Collins said only one customer’s card had been compromised and he couldn’t say with complete certainty that that person’s information was stolen in the Target data breach or elsewhere.

Some 250 or so Belmont Savings Bank customers were compromised in the data breach, said President and CEO Robert M. Mahoney.

Four Belmont employees came into the bank on their day off to sift through transaction data and identify those customers who had used their cards at Target during the three-week period. Those customers were automatically issued new cards, he said.

“But if they’re anxious, we’ll give them a new card right away,” he said.  

And Clinton Savings Bank opted to notify those customers whose cards might have been compromised and then let them decide what to do with that information – be it monitor their account for suspicious activity or order a new card altogether, Senior Vice President and Chief Information Officer Mike Penaglia said.

The holiday shopping season was a major factor in the bank’s decision, he said. The bank did not want to inconvenience its customers by imposing spending or withdrawal limits, or by making them wait seven to 10 business days for a new card to arrive by mail.

 

Underground As Barometer

The thieves who breached Target’s system stole the information encoded on the magnetic stripes on the backs of credit and debit cards. That data, known as “dumps,” is then sold in underground card shops online, and purchasers use it to clone the cards and use them in brick-and-mortar stores.

Krebs has written extensively about this practice, and other security and data issues, at KrebsOnSecurity.com.

“The underground has always been a barometer of what’s going on topside. In this case, the early alerts that I got, several of these card shops all of a sudden had a glut of cards to sell,” he said.

Chip and pin technology, currently more popular in Europe than America, could do more to deter this type of theft, but Krebs says that that’s still just a hurdle for determined miscreants.  

“More to the point, it raises the cost for the bad guys. It’s not that they can’t reproduce those cards, but now it barely costs anything. It’s the cost of a magnetic stripe reader and writer and a piece of plastic,” he said. “If they had to fabricate chips, it would be a lot more expensive.”

For Collins and other community bankers, it’s a sign of the times that they knew exactly how they would handle the situation.

“Unfortunately, there have been so many compromises that I think we’ve built in a good process on how to deal with these. We’re much more prepared to handle these types of things,” he said. “There have been so many of these compromises the customer seems to be used to it.”

 

Email: lalix@thewarrengroup.com

Community Banks Swoop In After Target Hacking

by Laura Alix time to read: 3 min
0