Fiserv, FiCare clash over passcodes in card-freeze fight

Fiserv Stock Tumbles Record 47% As Results Confound Wall Street
Caleb Santiago Alvarado/Bloomberg
  • Key insight: Fiserv's own lawyers say the company's system can unfreeze a card flagged for fraud before the call reaches an agent.
  • What's at stake: Criminals are taking advantage of this system to reactivate stolen cards, a credit union says.
  • Supporting data: Fiserv serves more than 3,330 credit unions.

Overview bullets generated by AI with editorial review.

Processing Content

Amid a monthslong lawsuit over cyberattacks that compromised credit union members' online banking accounts, lawyers for Fiserv recently told a Florida credit union that an automated phone system can unfreeze a card flagged for fraud before the call reaches a human.

Banks and credit unions across the industry use automated processes to lift fraud holds on cards. Automation helps ensure that every caller goes through the same checks, without room for human error.

The controversy in this case is that fraudsters have passed Fiserv's automated checks to reactivate stolen cards, according to FiCare Federal Credit Union. The credit union asked a federal judge in Tampa on Monday to bar Fiserv from using automated means to lift fraud holds on its cards.

FiCare's filings last week, reported by American Banker, described fraudsters talking Fiserv's agents into turning stolen cards back on. The new filings focus instead on the automated checks.

Three other credit unions told colleagues on an email list that they too were seeing fraudsters calling Fiserv's card services, posing as members, to get fraud holds lifted or fraudulent charges approved, according to exchanges FiCare attached to court filings.

The credit union wanted a ruling by Sept. 29. The judge instead ordered Fiserv to file a written response by Oct. 5.

Fiserv serves roughly 10,000 financial institutions, including more than 3,330 credit unions, according to its website. The filings do not say how many of them use the automated card unlocking flows.

How Fiserv says the calls are checked

A card frozen for a suspicious transaction triggers an alert to the cardholder from EnFact, Fiserv's fraud-alert system, according to a Sept. 24 email from Fiserv's outside counsel to FiCare's lawyer. FiCare filed the email in court.

The alert carries two important items: A case number and a callback number. The callback number is important because it is not always the same; it can differ between cases.

EnFact's automated phone system answers the callback number, according to Fiserv's email. It checks that the call came from the cardholder's phone number and that the caller dialed the phone number in the alert.

It also checks that the caller entered the case number, but as an alternative, EnFact also accepts the cardholder's full Social Security number.

If all three checks pass, "the card will be unfrozen," the email said.

If any check fails, the call goes to Fiserv's contact center. For debit cards, that starts with the contact center's own automated phone system; if it authenticates the caller, the agent needs only the caller's name.

Fiserv's email also said that the contact center checks whether the caller entered the alert's case number at the first step and, if not, requires extra verification.

For a credit union without one-time passcodes (random codes sent to the cardholder's phone or email), such as FiCare, Fiserv's email said the extra verification relies on "tokens related to the cardholder's account." The email does not say what those tokens are.

FiCare argues in its motion that caller ID can be spoofed and that criminals can get Social Security numbers through data breaches.

The one detailed example in the case

Court records in the case so far document just one call; a Fiserv support ticket that FiCare filed logs an Aug. 2 call that, according to FiCare, came from a fraudster.

The caller had already passed an automated check based on calling with the correct caller ID and providing the correct Social Security number, ZIP code, card security code and expiration date.

The agent asked only for the caller's name, went over three transactions that the caller confirmed as valid, and closed the case. Court records do not indicate which automated systems that call went through.

On the support ticket, FiCare asked Fiserv whether it was standard to close a case when the caller never gave the case number and no additional verification was done.

Fiserv replied that the caller had passed the automated checks, so only the name was needed.

Who should have turned on additional security?

Fiserv says FiCare had additional security measures available and passed on them.

A Fiserv senior director said in a sworn declaration that clients decide whether to use one-time passcodes and that FiCare "chose not to utilize" them.

Fiserv's counsel offered in the Sept. 24 email to switch passcodes on for FiCare "promptly." FiCare asked for them less than two hours later, according to an email chain that Fiserv filed.

FiCare's lawyer wrote in that email that the automated system "appears to remain insecure" even with passcodes, and in a court filing, FiCare argued that Fiserv offers passcodes only at the contact center and names no comparable safeguard for EnFact's automated phone system.

In its own brief to the court, Fiserv accused FiCare of making the filing as part of a publicity campaign and said a real security concern would not have been announced.

Fiserv did not immediately respond on the record to a request for comment. A Fiserv spokesperson said last week that the company intends to defend itself vigorously.

Credit unions compare notes

Credit unions that use Fiserv traded notes on an email list in the days before FiCare's Sept. 23 filing, and FiCare included that email chain in a court filing.

In the exchange, Torrington Municipal & Teachers Federal Credit Union said fraudsters were calling Fiserv's card services, posing as members, to close fraud cases. Somerset Federal Credit Union said it was experiencing the same.

Fiserv told MERCO Credit Union CEO David Ness that passcode authentication "only works for the Card Activation/PIN setting call center," he wrote in the email chain with the other credit unions. For the fraud-alert call center, Ness said Fiserv does not use one-time passcodes.

Fiserv's court filings describe a passcode option at its contact center, and they do not address the conflicting information Ness gave on that email chain.

Ness told American Banker last week that MERCO had "a few losses" in the past month and that Fiserv is investigating.

"Currently, I don't know if the problem is with our configuration or on the Fiserv side," Ness told American Banker.


For reprint and licensing requests for this article, click here.
Fiserv Fraud Litigation Credit unions Cyber Security Debit cards Vendor management Technology
MORE FROM AMERICAN BANKER
Load More