




MADISON, Wis. -
Research, though, tells a mixed story. In some areas-identity fraud for example-there has been a steady decline since 2003. This report examines industry fraud trends and recent research; threats to credit unions and their response; educational paradoxes and cultural changes; as well as fraud prevention as a competitive necessity. There is evidence that Americans have become more tolerant of fraud in the past 20 or so years, according to David Callahan, author of The Cheating Culture and co-founder of Demos, the public policy center. Making money became the dominant cultural force while income gaps have been increasing dramatically during this time. "Other values in our culture have been sidelined: belief in community; social responsibility, compassion for less able or less fortunate," Callahan said.
Credit unions are not immune to this malaise. Callahan's book recalls the 9/11 attack and the 4,000 members of Municipal Credit Union of New York who overdrew their accounts, some by as much as $10,000. Municipal could have shut down the ATMs, but to its credit, kept the cash access open, because families of firemen and policemen and others needed cash during this time of crisis.
What happens when the average American reads about the Enron and Arthur Anderson scandals and feels like the system is rigged? "You might just make up your own moral code," Callahan writes. "Maybe you'll cheat on your taxes... Maybe you'll misuse your expense account at work to afford a few little luxuries that are out of reach on your salary-and you'll justify this on the grounds that people running your company are taking home huge paychecks while you're making chump change."
Or maybe you'll take your chances on a brilliant business offer that is too good to be true. And later you'll find yourself a victim of a fraud or con game.
Fraud Capital Of The USA
Geography is destiny in matters of fraud and crime, even in these days of online crime. Some areas tend to favor-even nurture-fraud and Los Angeles is one of them. It has been called the fraud capital of the United States. The nation's second largest city of 3.8 million is a melting pot with a transient population and easy entry and exit by air, train, rail, car or bus.
Technology's evolution and changes in consumer behavior during the past 10 years have also contributed to the increase in fraud, according to Steve Punch, who, when he spoke with the Credit Union Journal, was CEO of the $344-million First City Credit Union in Los Angeles. Punch was recently named CEO at Pacific Services CU.
"The changes in consumer behavior and technology in the last 10 years have provided more opportunities for fraud and other criminal activities," Punch said. "The consumer may have eight or 10 relationships-a credit union, a bank, online banking and borrowing from a point of sale. You are putting a lot of information out there to a lot of people."
In this a la carte approach to financial services, consumers tend to view mailings and advisories on websites as "noise" and something to be ignored, Punch said. The "agent" is gone when using electronic services, yet consumers still expect their credit union to provide that oversight and safety.
"Some of these electronic service organizations may be selling personal information; you really don't know where this information is going," Punch said." "It could be going to a legitimate marketing company or to criminals. Even if it is going to marketing companies, it is often without your permission. Members have confidence that the credit union has performed due diligence over their data, but that confidence shouldn't be transferred to the retailer or restaurant."
That confidence has been misplaced as numerous data breaches indicate retailers are not performing due diligence with their data.
"Your security is only as good as its weakest link," Punch said. "In the past the retailer never bothered to verify a credit card which provided a port of entry for fraud artists."
The weak links are out of the credit union's control and leave the organization and members vulnerable to fraud, according to Punch. "I can't claim that we are protected to a level of unquestionable safety for our members, because we don't control the transaction chain or the chain of information custody."
Automation provides more facilities and opportunities for fraud. "When it was face-to-face, you had to present an ID, and you would face a video camera," Punch said. "When it is faceless over the Internet, it emboldens people to commit fraud and makes it easier to move money."
The decrease in face time also means consumers are not gaining the advice and education formerly available when transactions were conducted at a branch.
"I think it's fair to say there has been an increase in electronic transaction and information-based fraud," Punch said. "Part of it has to do with more sophisticated overseas criminals, part with competition among financial institutions to create convenience, and part with merchants who have few safeguards and want to capture as much information about consumers as possible for marketing purposes and income if they sell the information."
Man In The Middle
Phishing is tailor-made for the "sophisticated overseas criminal" that Punch attributes to the increase in transaction and information fraud. "There are a lot of young, technicall, savvy criminals in impoverished countries that are not worried a bit about getting caught," said Kelly Dowell, executive director of the Credit Union Information Security Professional Association (CUISPA).
Phishing is an effective form of online fraud in any country because it is relatively easy to buy a mailing list and e-mail to large number of people. The fraudster can remain anonymous by setting up an e-mail address at AOL, HotMail, or Gmail, making it difficult to trace.
"Even if the fraudster gets a very small percentage, they can make $2,000 or $3,000 with little work," Dowell said. "Kits are available on the Internet that show you how to do it."
Less than one year after multi-factor authentication solutions were in place, fraudsters were already working around these solutions with "man in the middle" attacks, according to Dowell.
The man in the middle attacks start out with a phishing e-mail designed to lure a member to a hacker's website, which looks identical to the credit union's site. The goal, of course, is to get the member to log in. As the member enters information, the phisher's website does the same on the credit union's site.
The response from the credit union's website is then passed back to the member making the session appear exactly as if you were on credit union's site. All the while, the hacker is observing the session.
Once logged in, the man in the middle or the hacker, has full control of the member's account and could initiate a funds transfer if desired. This could be done, unseen by the member, by passing back only what the hacker wants the member to see. "Man in the middle phish kits (DIY software) began appearing in the hacker community in early 2007," noted Dowell.
The level of sophistication and creativity continues to grow, especially in phishing attempts, said Jeff Marshall, VP of product development with Harland Financial's Cavion Plus unit.
"The first phishing attempts were laughable with poor grammar and page splitting," Marshall said. "Now we are seeing a clever social engineering twist. A phishing attempt is made to look like the original attempt with poor grammar; people will download it and say 'Look at this stupid site,' and a malicious code will be downloaded."
Other variations are phone calls whereby people will Google your name while you are on the phone with the fraudster, said Niles Bay, VP of professional services, credit union core systems, Harland Financial Solutions.
Mobile Banking & Fraud Prevention
It is no accident that voice-phishing and mobile banking are both on the rise. As the FFIEC locked down websites, telephone fraud became more promising. "Out-of-band authentication" is looking more and more appealing, said Kelly Dowell. Out-of-band solutions send quick text messages or calls to the member's cell phone to verify a log-in.
"By implementing strong authentication through the Internet channel, as well as an out of band process through a cellular channel on a device the account holder owns, it would be practically impossible for a hacker to exploit both simultaneously," Dowell said.
Others in the industry predict mobile banking will strengthen its authentication and will become as prominent-and follow a parallel though faster growth path-as online banking, according to Mark Sievewright, corporate SVP-market development with Fiserv.
"The pioneers of mobile banking are putting in place secure access tools and making sure that authentication tools are used to authenticate. We're about to live through a new wave of change in online banking," he said.
There are some 220 million Americans with cellphones. Mobile phone banking is in a similar stage where Internet banking was in 1994. "In 2007, mobile banking is at the same threshold, it won't take as long to mature," Sievewright observed. "We can learn lessons from how credit union members have adapted to online banking."
Paypal Mobile has a pilot project, whereby you first conduct a transaction, then you are called back to authenticate the transaction, he said. "You are given a pass code for future transactions. Security is guaranteed. If something happens, you are de-activated in seconds."
Mobile banking's popularity is inevitable, and the lessons of fraud prevention from online banking are clear, said Sievewright. Financial institutions that fail to offer mobile banking in the future will not be sitting at the same competitive table as those who do, Sievewright said.
To prepare for the near future, Sievewright suggests credit unions begin to take steps to adapt mobile banking on a pilot basis to members and learn as much about it as possible. "There are 83-million Americans, 19 years old or younger; they will want that kind of technology," Sievewright. "They will be surprised if you don't have it. They were born into it. They will go elsewhere if you don't have it."
Identity Fraud Drops
The industry experts interviewed for this report agreed that credit unions are doing an adequate job of protecting their member's data. Note that it is "adequate" and can be improved. The problem occurs when the data leaves the credit union-to a vendor, member, or another merchant.
Identity fraud has decreased from 2003 to 2007, according to Javelin Strategy & Research, a research firm in Pleasanton, California. Javelin interviewed more than 5,000 U.S. adults in October 2006, including 458 victims. Identity fraud is the unauthorized used of another's personal information to achieve illegal financial gain. Identity fraud can occur without identity theft, which is the unauthorized access to personal information. Identity theft can occur without identity fraud. For example, large-scale data breaches typically have 3% identity fraud.
As the chart, above left, indicates, identity fraud has decreased steadily from 2003 in number of victims, from about 10 million to an estimated 8.4 million in 2007.
Fraud amounts also declined from $53.8 billion in 2003 to an estimated $49.3 billion in 2007, according to Javelin Strategy & Research.
"The majority of online fraud is theft of access as opposed to actual ID theft," said Bruce Cundiff, senior analyst, Javelin. "A good example is TJMaxx; the online crime doesn't necessarily result in the victimization of individuals. A data breach is cited in 3% of ID fraud cases."
Young Adults At Risk For ID Theft
The Javelin survey also found that young adults between the ages of 18 and 24 years old were more at risk for ID theft.
They were less likely "than other adults to use basic precautions such as shredding, antivirus software and turning off paper statements, prior to their statements being compromised," according to the survey.
As a result the survey concludes, young adults were most likely to be the victims of fraud during the last 12 months compared to any other age group-5.27% versus 3.74% overall. Those who had an idea who might be the fraudster, 53% were friends, neighbors, or in-home employees, compared to 23% overall.
For credit unions seeking to attract that elusive demographic-the young adult-fraud prevention, education and risk management can be a sensible strategy.
Some banks are already offering anti-virus software to their customers. Since young adults are high tech users, providing anti-virus software solidifies the credit union's reputation as the trusted adviser.
Fraud Risks & Ethnicity
African-Americans have the highest fraud rate of fraud victims at 6.91%, according to the Javelin survey, and take the longest time to resolve fraud at 39 hours, but have the lowest fraud amount as shown in Figure B. (Editor: Page 26 Javelin Figure 15).
White/caucasians experience the lowest fraud rate at 2.76% and average 22 hours to resolve fraud. Asians have the highest fraud amounts at $8,496.
Education's Paradox
The key to fraud prevention is education and more education say the experts interviewed for this report. But member education has been a tough sell for credit unions; seminars on fraud and other subjects often play to empty chairs. Members tend to value education when they perceive a need or are facing an emergency-bankruptcy or a foreclosure.
This is not to devalue education; it has a key role in fraud prevention and NCUA's Letter 06-CU-13 directs credit unions to implement a program to "educate members on fraud prevention. Member education is critical to reduce fraud and identity theft. Current member education programs need to be evaluated to determine if additional steps are necessary."
"Education is a tough sell," said Dominick Nigro, NCUA information systems officer. "But if individuals had not been educated about phishing or pharming scams, the number of these scams would be significantly higher if we didn't have the education. It is important to have the educational process."
Counting on the member to keep his data secure may be unrealistic. The prudent strategy is to design systems and fraud protection without the expectation that members are being diligent about security, said Lewis Joram, senior product market manager for RSA, the Security Division, EMC.
"It is unfair to expect members to be diligent about security," Joram said. "Credit unions have to realize there is a balance. Some users will probably never take precautions; some might take a few, the vast majority of members will take precautions occasionally."
Many consumers view their PCs as a stove or refrigerator to be discarded at will. There are a growing number of venues to gain access to the Internet-airports, coffee shops, libraries-often with dubious security.
Consider posting tips on your website or newsletter (see story, page 19).
"It's like the Wild West now when you plug into the Internet," said Robert Brown, director of information services at Wescorp. "You can't assume members will follow security concerns; you can't assume the end user is secure."
Members are open to creative approaches to education. If the credit union educational efforts are reproducing government posters or hand-outs, the response will likely be lukewarm. Credit unions that have incorporated contests and other innovations have found receptive members.
Changing Culture
Just as 9/11 has changed the way we travel by air, fraud has changed the way we prepare and deter fraud. It has spawned innovative business lines. Digital forensics, which didn't exist a few years ago, examines digital media and determines whether it has been manipulated.
A digital forensic expert decides if an image has been doctored in a court disposition. As financial institutions have been able to combat phishing attempts in text-based messages, fraudsters are now using embedded images; this skill may be needed in the future. The well-worn Nigerian 419 scam now uses embedded images.
The most noticeable change in credit union culture is identification of members. "A few years ago, a member would call his credit union and ask for account information; credit union personnel would ask for an account number," said Dominick Nigro. "Today members are asked multiple questions to establish their identity and could be asked additional questions to authenticate themselves if the types of transactions warrant additional steps."
There are additional changes that are invisible to the member such as firewalls, intrusion prevention systems, and internal controls such as Microsoft Active Directory to monitor systems and limit access to sensitive member and credit union information, said Nigro.
NCUA required credit unions to improve their authentication of members by year-end 2006 to follow guidelines of Federal Financial Institutions Examinations Council (FFIEC). Credit unions that implemented multi-factor authentication have had problems-some 80% of credit unions surveyed reported that they will readdress their multi-factor authentication, according to a survey by CUISPA and reported in the CU Journal (Sept 17).
FORUM Credit Union, Indianapolis, was seeking an authentication solution for its 100,000 members that would balance security with convenience.
"We wanted a solution that was transparent, but one that was the least intrusive," said Doug True, SVP of technovation. "And we already had 60,000 members as active users on our Internet banking solution."
The $1-billion credit union chose a solution that authenticates based on a user's typing rhythm called BioPassword, which was little used in the financial services industry, but used extensively in the health industry. In 2006, the BioPassword solution was launched at FORUM whereby employees used this authentication to gain access to their PC at work.
"Since a lot of fraud happens in person, by a janitor or a visitor, someone you know, we wanted something secure, said True. "Fighting fraud starts with employees-PC post-it notes and other similar items."
BioPassword was introduced in the Internet banking solution in September 2007. The first time members logged-in they were asked to repeat the log-in nine times to build their template in which the rhythm is compared. "Some of the members were irritated, even though they had an option to gradually enroll and build their template over time," said True.
Any change to an Internet banking solution brings on stress for a portion of the membership. Some of the changes related to an enhancement that took the internet banking solution from an account based solution to a user based one. "The change to a user based solution allows the member to interact with all of their credit union accounts, even ones they are joint on or a secondary account on one screen," he said.
"I personally responded to all of the calls-about 40 members." True said. "We've learned from this process, that we have to explain why we are doing this. You need to build your template over time. There is a delicate balance between security and convenience."
Some organizations are passing on e-mail marketing because phishing attempts are so effective, according to "Emerging Marketing Channels," a soon-to-be published white paper by the CUNA Marketing Council.
"E-mail marketing is fraught with a lot of risk; it is easy to replicate your offer with phishing," said Stephen Black, director of marketing at BECU in Tukwila, Wash. "Phishing scams are so effective it looks like it is coming from BECU."
Board's Evolving Role In Fraud Prevention
As fraud is changing the culture and operations, the role of the director is evolving especially in crafting policies, according to Tom DeSot, EVP vulnerability research and regulatory affairs with San Antonio-based Digital Defense.
"Policies should clearly state what types of information credit unions will ask members, and what, if any, information, can be asked by e-mail," he said.
It is cost effective for a credit union to communicate to members by e-mail, but the majority of e-mail is not encrypted so it can be captured. "Policies should state what a staff member can e-mail to a member, for example, if he can send a member's account number and balance," said DeSot. "Fraudsters look for that information on the Internet."
The supervisory committee plays a major role in fraud prevention by overseeing risk analysis and risk prevention said John Gregoire, president of Pro-Con Group in Madison, Wis..
"The committee ensures that the organization is doing its due-diligence in fraud prevention," he said. "Each supervisory committee member should receive an annual audit plan to review the various operations of the credit union. The plan should be prioritized based on risk."
The supervisory committee should have qualified people who understand their role and report back to the board on a regular basis, said Gregoire. The board also needs to determine the credit union's tolerance for risk as some credit unions have more tolerance for risk than others, he said.
Security & Vendors
A credit union may have 30 or more vendors or partners with varying degrees of protecting the credit union's s data. During times of thin margins, credit unions are also looking for ways to cut costs with a different vendor.
"We may be enthralled by a product, but we need to have a clear idea of what our expectations are," said Tom Glatt, CEO at the $180-million Continental FCU in El Segundo, Calif. "We need to have meetings every step of the way-pre-implementation, implementation, and post-implementation."
The important question to ask is if you are satisfied with the result of the product. "Are you happy with it or you just living with it?" said Glatt. "As credit unions we are terrible negotiators; we assume all of the risks."
All of the protections should be put into the contract, including training, performance standards, ability to exit, extended warranty, and legal remedies, said Glatt. "I won't sign any contract that doesn't go through a legal review." Glatt uses a California legal firm that specializes in credit unions legal issues.
One of the drawbacks that Glatt points to and with which others in the industry concur is the lack of sharing information about vendors among credit unions.
A valid point-a common database that credit unions could access and share information on vendors would be helpful to separate the wheat from the chaff. Kelly Dowell agrees.
"Currently, each credit union assesses their own vendors with their own due-diligence procedures," said Dowell.
"Meanwhile, each vendor is responding to each of their customers, individually. What we have now is a very inefficient process requiring a lot of time from both parties."
The crux of the problem is there are "no common standards or documented best practices leaving each credit union on their own to determine how to evaluate their vendor relationships," said Dowell.
"This is one of those things that require an industry-wide effort, and with such an effort we can greatly improve the process," Dowell said, noting that the CUISPA is developing a shared vendor risk management program that will be available in 2008.
In Wisconsin, credit unions share information about vendors on the league's listserv. They can get information about "experiences that worked," said WCUL CEO Brett Thompson. A common database of vendor information might be problematic, he said.
"It could be valuable, but I don't know how it could be done," he said. "It is always important to do an independent due diligence. A vendor of three years ago could be very different today. Your credit union needs could be different."
Thinking & Acting As Big Dogs
On July 16, the CU Journal published "Will Only the Big Dogs Survive?" which discussed the large credit unions' economies of scale that have increased exponentially.
Smaller credit unions are increasingly unable to offer member benefits of their larger brethren.
The costs of technology-in theory a great leveler-are in practice a prohibitively expensive factor.
Regardless of size, all credit unions have to invest in similar tools to prevent fraud. Considering online fraud this includes multi-factor authentication, firewalls, and fraud detections-all at sizeable expense.
It is a cost that is expensive regardless of size. Are small credit unions similarly burdened in the fight against fraud? Size does make a difference said Javelin's Bruce Cundiff.
"Potentially, small credit unions may not have the resources for the latest technology," he said. "Five years ago it was more labor intensive for phishing, now it is not as labor intensive; phishing sites are easier and less expensive."
"Small credit unions, especially those under $50 million in assets on a PC-based platform, may not have the expertise or money to buy the necessary technology needed," said Pacific Service credit union's Steve Punch. "It is important for small credit unions to band together on a league or CUSO level for security purposes. Smaller credit unions will need to do it to survive."
Smaller credit unions had held the mistaken view that fraudsters are less likely to use phishing attacks against their organizations because their size made it unprofitable to attack. That may have been true in the past, but no longer, according to Tim Woolridge, vice president virtual branch, IntegraSystems.
"Phishing scams are moving further down the small credit union chain, hitting smaller credit unions," said Woolridge. "Small credit unions think they are immune because they are smaller, they are not a target. They are running a real risk if they believe this."
Bruce Cundiff agrees that at one time small credit unions were "somewhat" immune to phishing, but the speed of technology allows fraudsters to put up phishing sites quickly.
Research for the first five months of 2007 would appear to back this up as shown in the chart on page 20.
Credit union phishing attacks increased steadily.
PHISHING ATTACKS AGAINEST U.S. FINANCIALS
01/07 02/07 03/07 04/07 05/07
Nationwide US Banks 31% 19% 16% 17% 33%
Regional US Banks 46% 55% 53% 55% 28%
US Credit Unions 23% 26% 31% 28% 39%
Source: RSA Monthly Online Fraud Report
Competitive Necessity
JMaxx and other data breaches in 2006 represented a tipping point for the American consumer. The number of records compromised reached 100 million-or one third of all Americans, according to the New York Times. This raised the awareness and emotional thermometers of the consumer and changed forever the way fraud is perceived.
The California and Nevada Credit Union League's 2007 WestScan's Report's chapter on data security called computer-related fraud a disruptive technology:
"A case can be made that multiple data breaches in the past few years have transformed computer-related fraud into a disruptive technology for financial institutions. Not all records fell into the hands of criminals, of course, but identity theft, credit card and debit card fraud, as well as phishing, are changing the way financial institutions are securing data and managing business."
Members are acutely aware of this disruption and expect their credit union to protect their data. They are unfamiliar with the details that go into firewalls or encryption but they will be aware of a data breach that compromises their credit. Members want their financial institutions to demonstrate that they are protecting them against fraud, said Mark Sievewright.
"We are coming to a point where security is a competitive necessity," he said. "In the past we never thought of fraud prevention as a competitive issue. With the advent of sophisticated fraud tools, consumers are more conscious about safety."
There are a number of initiatives that credit unions should consider. For example, Bank of America is offering anti-virus software to its customers.
"Some financial institutions have said, 'this is not our space,' but frankly, perhaps it is," said Sievewright. "As a trusted financial adviser you want to be helping the members secure the online space."










