SOUTH BEND, Ind. – Officials of 1st Source Bank yesterday conceded that a security breach of its debit card server last month almost certainly is the cause of a growing number of fraudulent activities at area credit unions and banks that are being tapped into from overseas.
“When you piece it all together, it appears that there may be a link between our breach and those transactions,” James Seitz, a spokesman for the bank, told The Credit Union Journal yesterday.
The link appears to be the bank’s fleet of local ATMs, which are used by area credit unions and banks. The institutions say all of the affected account holders appear to have used a 1st Source Bank ATM last month. The largest number of victims, as many as 250, appear to be members of Teachers CU, which is located across the street from 1st Source Bank.
The 1st Source Bank officials said they met Monday with their credit union and bank clients to discuss the breach, after notifying all of the card companies, including MasterCard, Visa, Discover, American Express and Diner’s Club. The card companies, in turn, sent out lists of potentially compromised cards to each of the institutions.
Under Indiana law, a party that is responsible for a breach must notify its customers. Seitz said they have complied with the law by notifying their credit union and bank customers. “It’s up to each of them to notify their cardholders,” said Seitz, explaining that they do not have access to each credit union’s or bank’s cardholders.
Meantime, the breadth of the breach appears to be growing. Cardholders at at least a dozen area institution, including Teachers CU, Notre Dame FCU, Ball State FCU, Chiphone FCU, Farm Bureau CU, Allegius CU, as well as Chase Bank, Wells Fargo, National City Bank, Lake City Bank, Key Bank, Michiana’s Finest Bank, H&R Block Debit Card and E-Trade Financial.
The cardholders’ data, account numbers and PINs, are being used to manufacture bogus cards and to withdraw cash at ATMs all over the world, in Russia, Ukraine, Spain, the Philippines, Kenya, Nigeria, Turkey, Cyprus and the Czech Republic.
Teachers CU has recorded approximately $50,000 in fraudulent transactions on its members’ accounts, a loss too small to make a claim on its fidelity bond, said Richard Rice, president of the $1.8 billion credit union. Rice said he hopes the responsible party will pay the costs.
Likewise, Notre Dame FCU’s loss of $15,000 to $20,000 probably is too small to file an insurance claim, according to Leo Ditchcreek, president of the $400 million credit union.
Like most credit unions, Teachers CU and Notre Dame FCU have a zero loss policy that reimburses members for all fraud losses on their cards.
1st Source Bank’s Seitz said it will comply with MasterCard and Visa rules on liability for breaches, but he would not elaborate. “MasterCard and Visa have their own rules on this,” he said.











