February 7, 2017 By Mark Samuels 2 min read

Chip-and-PIN cards were introduced in the U.S. in October 2015. In response to increased security in retail stores, cybercriminals have moved online and e-commerce fraud has risen accordingly, according to Computerworld.

The latest “Global Fraud Attack Index” from PYMNTS revealed that U.S. e-commerce fraud has risen 42 percent since the fourth quarter of 2015. Retailers must be alert to this increase and focus on helping consumers stay safe online.

Building Evidence

According to the study, the total number of dollars at risk from online retail fraud rose 55 percent from the second quarter of 2015 to the second quarter of 2016. This represents an increase from $4.90 to $7.60 per $100 of online sales. The risk figure was as high $12.20 for the sale of luxury goods.

The study also found that the rate of attacks featuring botnets increased 47 percent between the third quarter of 2015 and the second quarter of 2016. For luxury goods, that figure was up by 87 percent.

The Computerworld article also cited recently released figures from Javelin Strategy & Research, which revealed that U.S. identity fraud hit a record high in 2016, with 15.4 million victims and a year-over-year rise of 16 percent. Digitally connected consumers are at higher risk of identity fraud, the report said.

Explaining the Increased Online Threat

Mike Lynch, chief strategy officer at security firm InAuth, told Computerworld that his firm had expected e-commerce fraud to rise following the introduction of chip-and-PIN cards. He said other countries noted similar jumps in online fraud following this adoption.

The Javelin study also found that the increased use of chip cards and terminals was a catalyst for driving fraudsters online and toward new forms of e-commerce fraud. Al Pascual, research director in fraud and security for Javelin, said in a company statement that attackers always adapt and find new approaches.

“The rise of information available via data breaches is particularly troublesome for the industry and a boon for fraudsters,” said Pascual. “To successfully fight fraudsters, the industry needs to close security gaps and continue to improve and consumers must be proactive too.”

Keeping Customers Safe From E-Commerce Fraud

Strong partnerships between consumers and financial institutions can help to lessen the impact of fraud. Javelin suggested seven safety tips to help protect customers:

  1. Be smart on social media. Review your settings to ensure your profile is only open to verified connections, and do not accept friend requests from strangers.
  2. Protect online shopping accounts. Enabling two-factor authentication on e-commerce sites makes it more difficult for fraudsters to take over your accounts.
  3. Exercise good password habits. Strong, unique, regularly updated passwords help reduce the risk of fraud — and the value of stolen account details.
  4. Place a security freeze. A freeze on your credit report, which can be lifted on request, prevents anyone else from opening an account in your name.
  5. Sign up for account alerts. These alerts can often be received through email or text message, making some notifications immediate.
  6. Be alert for online transactions. E-commerce fraud gives cybercriminals a platform to make many transactions quickly, so early detection can help reduce losses.
  7. Seek help as soon as fraud is detected. Early notification can limit a victim’s liability and provide law enforcement teams with more time to catch fraudsters.

More from

How to calculate your AI-powered cybersecurity’s ROI

4 min read - Imagine this scenario: A sophisticated, malicious phishing campaign targets a large financial institution. The attackers use emails generated by artificial intelligence (AI) that closely mimic the company's internal communications. The emails contain malicious links designed to steal employee credentials, which the attackers could use to gain access to company assets and data for unknown purposes.The organization's AI-powered cybersecurity solution, which continuously monitors network traffic and user behavior, detects several anomalies associated with the attack, blocks access to the suspicious domains…

Being a good CLR host – Modernizing offensive .NET tradecraft

14 min read - The modern red team is defined by its ability to compromise endpoints and take actions to complete objectives. To achieve the former, many teams implement their own custom command-and-control (C2) or use an open-source option. For the latter, there is a constant stream of post-exploitation tooling being released that takes advantage of various features in Windows, Active Directory and third-party applications. The execution mechanism for this tooling has, for the last several years, relied heavily on executing .NET assemblies in…

The current state of ransomware: Weaponizing disclosure rules and more

4 min read - As we near the end of 2024, ransomware remains a dominant and evolving threat against any organization. Cyber criminals are more sophisticated and creative than ever. They integrate new technologies, leverage geopolitical tensions and even use legal regulations to their advantage.What once seemed like a disruptive but relatively straightforward crime has evolved into a multi-layered, global challenge that continues to threaten businesses and governments alike.Let’s take a look at the state of ransomware today. We’ll focus on how cyber criminals…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today