advertisement
advertisement

This is page 2 of:

Duplicate Debit Debacle Hits Best Buy, Macys. Who’s Next?

March 18th, 2009

Indeed, Best Buy refunded Williams for the extra charges. Williams said the retailer also promised it would send him a $75 check to pay for penalties he was accessed by the bank in the days after the incident because several of his checks, including one for a car payment, bounced.

Best Buy Stands By Its Statement

In an interview conducted before Best Buy decided to merely “stand by” its statement, Nezworski said she thought the cashier’s second and third swipes of Williams’ card “were incorrect” as a store practice. However, she also said the transaction wasn’t allowed to go through until after the store contacted Visa and received an authorization.

Orrock said he could envision several explanations for Williams’ experience, and most of those explanations “have to do with error codes being properly translated.” Perhaps the acquirer might have received a code from a system in the middle saying the transaction was taking too long and timed out. He said the message that Williams exceeded his daily limit, an unusual message for a POS to see, could have been caused by a mistranslation of the ‘response code’ as the message is passed back from institution to institution.”

As for the systems designed to watch for and prevent these kinds of duplicate charges, those systems are only as effective as the data they are allowed to access. Orrock said, for example, that payment processing systems rarely check product codes to see if the same product is being paid for multiple times. “I build some big POS systems and we are not checking SKUs,” Orrock said. “We are not checking product codes. Payment switches are not getting down to that level.” He also noted that, if the first attempted transaction was recorded by Best Buy as a denial of some sort, but approved by the issuer, the system would not see a subsequent attempt as being a duplicate because it thought the first one was rejected.

The Best Buy system might have done everything properly but could have been dealing with garbled information from somewhere else in the complex process. “What (codes) the issuer passes back and what ends up at the POS can sometimes be entirely different,” Orrock said. “A lot of things have to right for that to work. My 2-digit codes might not be the same as the next guy in the chain. You’re dependent on everybody making the right translations.”

While not particularly commonplace, Orrock said PIN debit system hiccups are not totally rare, especially when store clerks swipe cards multiple times. “You do see situations like this where, for one reason or another, all the actors involved in the transaction did not discharge their duties properly,” Orrock said. “I could concoct a scenario for you that fits what happened to this guy with absolutely no problems evidenced by Best Buy. Best Buy could be totally in the dark, in a good way, about what happened. They would get something back that indicates the transaction was rejected or denied. They get a response code and throw it on screen. In the meantime, behind the scenes, the issuer authorized the transaction.”

Orrock urged retailer CIOs to “pay attention” to their systems suspense file. “What ends up happening in debit is, you typically provide the gateway with a list of all the transactions you think you consummated during the day and the gateway is going to match those transactions up. If there are any differences between the file you sent and what the gateway processor thinks they processed online, those items are going to fall out and go to the suspense report. You must pay attention to the items on there, the spurious items.”


advertisement

3 Comments | Read Duplicate Debit Debacle Hits Best Buy, Macys. Who’s Next?

  1. Greg Patrick Says:

    When you swipe your swipe your card. Ask for an error message, call your bank before swiping your card again. If you are going to use a debit card, do not write checks.

  2. Terry Bouvier Says:

    Almost all banks/transaction processors in the world have the inherent flaw that caused the scenario described above. They approve the credit/debit transaction and then pass this message to the POS and then assume they’ve done their part and all is well. There are some additional checks behind the scenes to determine if the message was successfully received, but there is still a small window of opportunity for failure.
    HSBC is the only bank I’ve seen whereby they require the POS system to respond with a message stating “Yes, I’ve received your approval message and here is the approval code you just sent me which proves I actually received your message – all is well”. If the bank does not receive this message within a certain time, it will assume all was not well and will reverse the last transaction.
    The chance of failure in this scenario is about the same as in the scenario at Best Buy and Macy’s however, the liability is shifted from the consumer to the retailer. Instead of the customer being double/triple charged, it is possible they walk out with free merchandise. This of course, raises the argument is it better to annoy a loyal customer (who will notice being overcharged) or take the hit where it might not be noticed (unless the retailer is diligently monitoring their suspense/settlement files). Most retailers prefer the former since they know they can make amends. If a customer walks away with free merchandise, it may be impossible to ever collect that money.
    The bottom line – monitor your bank statements regularly and refute all questionable transactions. The onus is on the retailer to prove you authorized the charges.

  3. Bruce Daughtry Says:

    Interesting that this double posting issue with debit cards keeps happening. My daughter’s debit card was double billed by AT&T when she bought the iPhone 3G. Apparently only debit cards were affected, according to AT&T, and happened to a lot of people.

Newsletters

StorefrontBacktalk delivers the latest retail technology news & analysis. Join more than 60,000 retail IT leaders who subscribe to our free weekly email. Sign up today!
advertisement

Most Recent Comments

Why Did Gonzales Hackers Like European Cards So Much Better?

I am still unclear about the core point here-- why higher value of European cards. Supply and demand, yes, makes sense. But the fact that the cards were chip and pin (EMV) should make them less valuable because that demonstrably reduces the ability to use them fraudulently. Did the author mean that the chip and pin cards could be used in a country where EMV is not implemented--the US--and this mis-match make it easier to us them since the issuing banks may not have as robust anti-fraud controls as non-EMV banks because they assumed EMV would do the fraud prevention for them Read more...
Two possible reasons that I can think of and have seen in the past - 1) Cards issued by European banks when used online cross border don't usually support AVS checks. So, when a European card is used with a billing address that's in the US, an ecom merchant wouldn't necessarily know that the shipping zip code doesn't match the billing code. 2) Also, in offline chip countries the card determines whether or not a transaction is approved, not the issuer. In my experience, European issuers haven't developed the same checks on authorization requests as US issuers. So, these cards might be more valuable because they are more likely to get approved. Read more...
A smart card slot in terminals doesn't mean there is a reader or that the reader is activated. Then, activated reader or not, the U.S. processors don't have apps certified or ready to load into those terminals to accept and process smart card transactions just yet. Don't get your card(t) before the terminal (horse). Read more...
The marketplace does speak. More fraud capacity translates to higher value for the stolen data. Because nearly 100% of all US transactions are authorized online in real time, we have less fraud regardless of whether the card is Magstripe only or chip and PIn. Hence, $10 prices for US cards vs $25 for the European counterparts. Read more...
@David True. The European cards have both an EMV chip AND a mag stripe. Europeans may generally use the chip for their transactions, but the insecure stripe remains vulnerable to skimming, whether it be from a false front on an ATM or a dishonest waiter with a handheld skimmer. If their stripe is skimmed, the track data can still be cloned and used fraudulently in the United States. If European banks only detect fraud from 9-5 GMT, that might explain why American criminals prefer them over American bank issued cards, who have fraud detection in place 24x7. Read more...

StorefrontBacktalk
Our apologies. Due to legal and security copyright issues, we can't facilitate the printing of Premium Content. If you absolutely need a hard copy, please contact customer service.