advertisement
advertisement

This is page 2 of:

Letting Customers Chase Your Thieves Gets Something More Valuable Than A Nabbed Thief: A Loyal and Happy Customer

November 8th, 2011

So why not let them help you?

About a year ago, I was called by my credit-card company and asked if I had authorized a charge in some small town in North Carolina. I hadn’t. But rather than simply saying “no” and getting a new card, I said, “hmm… I don’t think so. Tell me more about the charges.” The clerk was able to tell me the address of the merchant, the nature of the charges, the items purchased and even the register from which the charge was made.

We went back and looked at other charges, and found four charges within about an hour in various cities in North Carolina. Google Maps told me where these cities were, and I was able to plot out where the bad guy was going. One of the charges had occurred within 15 minutes.

Using Google street view, I pulled up a picture of the offending shop and looked up the address. I called each store and had them tell me whatever they could recall about the person making the unauthorized charge. A gas station had video, which I asked them to preserve. I then looked up the name and telephone number of the local sheriff’s office and called them and asked them to look at the surveillance videos at the three stores.

I asked the credit-card company not to put a hold on my card but to put an alert on it, and to text me each time it was used (for about four hours—and then cancel the card).

As a result of this brilliant detective work, nothing at all happened. Nobody was caught, nobody was arrested, nothing. But I felt a lot better, and I was willing to try to find the “thief.” I doubt that Bank of America would have done the same thing for what amounted to a few hundred dollars of charges.

A similar thing happened about 10 years ago, when I was called by Citibank about a mortgage I had apparently applied for in a city about 40 minutes away. When I told the bank it was unauthorized, they refused to provide me with any additional information about the application—citing the privacy of the thief—until I called them back, playing dumb, and “asked about this mortgage I applied for.” I was able to get the address the thief used and the other personal information that person supplied (my social security number, but that person’s other information), and even went to the post office in that person’s city and put in a change of address form for myself (any mail addressed to me at that person’s address would be rerouted back to me at my real address).

Immediately, I started getting credit-card and other applications that person had requested. Long story short, the information had come from an affinity card I had applied for, and the bad guy had stolen hundreds of social security numbers.


advertisement

2 Comments | Read Letting Customers Chase Your Thieves Gets Something More Valuable Than A Nabbed Thief: A Loyal and Happy Customer

  1. Tom Mahoney Says:

    I absolutely agree with you. Anything less than getting your customers involved is like watching someone get beaten in front of your house while you do nothing.

    If more merchants and customers got involved, I think we’d see a less cyber-crime. As you mentioned, privacy issues and all the other excuses are tossed around and anonymity runs wild.

    Merchants, service providers, and all the others need to share information. It’s proven to make things happen. Programs like Ethoca’s FraudStop have proven it.

  2. Biff Matthews Says:

    Unfortunately, no one of importance, the merchant much less the police or card issuers and associations, are interested in pursuing these criminals. Criminals know this so they continue to operate with reckless abandon. UNTIL someone in one of those entities or who is high profile is compromised, then it’s Katie, bar the door.
    If you remember the article about how one broken window leads to another then to more vandalism and crime you see how important it is to pursue, apprehend and punish to the greatest extent possible the small time hacker you send a strong message that this activity will not be tolerated at any level, hence diminishing the overall problem. Yes it takes investing a dollar on dime issue but dime make dollars and dollars left unprotected leads to hundreds of dollars of problem.

Newsletters

StorefrontBacktalk delivers the latest retail technology news & analysis. Join more than 60,000 retail IT leaders who subscribe to our free weekly email. Sign up today!
advertisement

Most Recent Comments

Why Did Gonzales Hackers Like European Cards So Much Better?

I am still unclear about the core point here-- why higher value of European cards. Supply and demand, yes, makes sense. But the fact that the cards were chip and pin (EMV) should make them less valuable because that demonstrably reduces the ability to use them fraudulently. Did the author mean that the chip and pin cards could be used in a country where EMV is not implemented--the US--and this mis-match make it easier to us them since the issuing banks may not have as robust anti-fraud controls as non-EMV banks because they assumed EMV would do the fraud prevention for them Read more...
Two possible reasons that I can think of and have seen in the past - 1) Cards issued by European banks when used online cross border don't usually support AVS checks. So, when a European card is used with a billing address that's in the US, an ecom merchant wouldn't necessarily know that the shipping zip code doesn't match the billing code. 2) Also, in offline chip countries the card determines whether or not a transaction is approved, not the issuer. In my experience, European issuers haven't developed the same checks on authorization requests as US issuers. So, these cards might be more valuable because they are more likely to get approved. Read more...
A smart card slot in terminals doesn't mean there is a reader or that the reader is activated. Then, activated reader or not, the U.S. processors don't have apps certified or ready to load into those terminals to accept and process smart card transactions just yet. Don't get your card(t) before the terminal (horse). Read more...
The marketplace does speak. More fraud capacity translates to higher value for the stolen data. Because nearly 100% of all US transactions are authorized online in real time, we have less fraud regardless of whether the card is Magstripe only or chip and PIn. Hence, $10 prices for US cards vs $25 for the European counterparts. Read more...
@David True. The European cards have both an EMV chip AND a mag stripe. Europeans may generally use the chip for their transactions, but the insecure stripe remains vulnerable to skimming, whether it be from a false front on an ATM or a dishonest waiter with a handheld skimmer. If their stripe is skimmed, the track data can still be cloned and used fraudulently in the United States. If European banks only detect fraud from 9-5 GMT, that might explain why American criminals prefer them over American bank issued cards, who have fraud detection in place 24x7. Read more...

StorefrontBacktalk
Our apologies. Due to legal and security copyright issues, we can't facilitate the printing of Premium Content. If you absolutely need a hard copy, please contact customer service.