Jump to content

RFID skimming: Difference between revisions

From Wikipedia, the free encyclopedia
Content deleted Content added
AnomieBOT (talk | contribs)
m Dating maintenance tags: {{When?}} {{Which?}}
GYlva (talk | contribs)
m Undid revision 944373027 by AnomieBOT (talk)
Line 3: Line 3:
'''RFID [[Skimming (fraud)|skimming]]''' is a method to unlawfully obtain someones payment card information.
'''RFID [[Skimming (fraud)|skimming]]''' is a method to unlawfully obtain someones payment card information.
== How RFID skimming is performed ==
== How RFID skimming is performed ==
Modern{{Which?|date=March 2020}} payment cards have a built in chip that transmits the cards&#39; information wirelessly. This is because it is necessary in order to enable [[Contactless payment|contactless payments]], which has become increasingly popular during recent years<ref>{{Cite web|url=https://www.visaeurope.com/newsroom/news/1-billion-visa-contactless-purchases-made-in-last-year|title=1 billion Visa contactless purchases made in last year|website=www.visaeurope.com|access-date=2019-01-06}}</ref>. Criminals can take advantage of this new technology by using a scanner that wirelessly scans the victim&#39;s payment card in the same way that a cash register scans it, when making a contactless payment. These scanners are legal and can be bought in regular electronics stores<ref>{{Cite web|url=https://www.amazon.co.uk/dp/B00F91ONV2/ref=asc_df_B00F91ONV257881850/?tag=googshopuk-21&creative=22146&creativeASIN=B00F91ONV2&linkCode=df0&hvadid=309904628368&hvpos=1o1&hvnetw=g&hvrand=611162221074075592&hvpone=&hvptwo=&hvqmt=&hvdev=c&hvdvcmdl=&hvlocint=&hvlocphy=9045935&hvtargid=pla-577620202982|title=NFC RFID Reader / Writer ACR122U ISO 14443A/B + Free Software in White: Amazon.co.uk: Beauty|website=www.amazon.co.uk|access-date=2019-01-06}}</ref>.
Modern payment cards have a built in chip that transmits the cards&#39; information wirelessly. This is because it is necessary in order to enable [[Contactless payment|contactless payments]], which has become increasingly popular during recent years<ref>{{Cite web|url=https://www.visaeurope.com/newsroom/news/1-billion-visa-contactless-purchases-made-in-last-year|title=1 billion Visa contactless purchases made in last year|website=www.visaeurope.com|access-date=2019-01-06}}</ref>. Criminals can take advantage of this new technology by using a scanner that wirelessly scans the victim&#39;s payment card in the same way that a cash register scans it, when making a contactless payment. These scanners are legal and can be bought in regular electronics stores<ref>{{Cite web|url=https://www.amazon.co.uk/dp/B00F91ONV2/ref=asc_df_B00F91ONV257881850/?tag=googshopuk-21&creative=22146&creativeASIN=B00F91ONV2&linkCode=df0&hvadid=309904628368&hvpos=1o1&hvnetw=g&hvrand=611162221074075592&hvpone=&hvptwo=&hvqmt=&hvdev=c&hvdvcmdl=&hvlocint=&hvlocphy=9045935&hvtargid=pla-577620202982|title=NFC RFID Reader / Writer ACR122U ISO 14443A/B + Free Software in White: Amazon.co.uk: Beauty|website=www.amazon.co.uk|access-date=2019-01-06}}</ref>.


Most{{Which?|date=March 2020}} modern{{When?|date=March 2020}} mobile phones running Android OS have a built in NFC reader that can be used to unlawfully scan contactless payment cards<ref>{{Cite web|url=https://play.google.com/store/apps/details?id=com.charm.android.nfc_emv_card_info&hl=en_US|title=EMV Card Reader - Apps on Google Play|website=play.google.com|language=en|access-date=2019-01-06}}</ref>. A criminal can hide the scanner e.g. inside a glove or a bag, and then place himself close to the victim and wirelessly steal the victim&#39;s payment card information<ref>{{Cite news|url=https://www.theguardian.com/money/2015/jul/23/contactless-card-is-too-easy-says-which|title=Contactless card fraud is too easy, says Which?|last=Bachelor|first=Lisa|date=2015-07-23|work=The Guardian|access-date=2019-01-06|language=en-GB|issn=0261-3077}}</ref>.
Most modern mobile phones running Android OS have a built in NFC reader that can be used to unlawfully scan contactless payment cards<ref>{{Cite web|url=https://play.google.com/store/apps/details?id=com.charm.android.nfc_emv_card_info&hl=en_US|title=EMV Card Reader - Apps on Google Play|website=play.google.com|language=en|access-date=2019-01-06}}</ref>. A criminal can hide the scanner e.g. inside a glove or a bag, and then place himself close to the victim and wirelessly steal the victim&#39;s payment card information<ref>{{Cite news|url=https://www.theguardian.com/money/2015/jul/23/contactless-card-is-too-easy-says-which|title=Contactless card fraud is too easy, says Which?|last=Bachelor|first=Lisa|date=2015-07-23|work=The Guardian|access-date=2019-01-06|language=en-GB|issn=0261-3077}}</ref>.


With the wirelessly obtained payment card information, the criminal can use it to make fraudulent purchases online{{Citation needed|date=March 2020}}. This is called [[Card not present transaction|Card Not Present]] fraud.
With the wirelessly obtained payment card information, the criminal can use it to make fraudulent purchases online{{Citation needed|date=March 2020}}. This is called [[Card not present transaction|Card Not Present]] fraud.

Revision as of 14:30, 11 March 2020

RFID skimming is a method to unlawfully obtain someones payment card information.

How RFID skimming is performed

Modern payment cards have a built in chip that transmits the cards' information wirelessly. This is because it is necessary in order to enable contactless payments, which has become increasingly popular during recent years[1]. Criminals can take advantage of this new technology by using a scanner that wirelessly scans the victim's payment card in the same way that a cash register scans it, when making a contactless payment. These scanners are legal and can be bought in regular electronics stores[2].

Most modern mobile phones running Android OS have a built in NFC reader that can be used to unlawfully scan contactless payment cards[3]. A criminal can hide the scanner e.g. inside a glove or a bag, and then place himself close to the victim and wirelessly steal the victim's payment card information[4].

With the wirelessly obtained payment card information, the criminal can use it to make fraudulent purchases online[citation needed]. This is called Card Not Present fraud.

Incidence

Card not present fraud has increased rapidly between 2012-2016[5].

In the United Kingdom an increase could be seen in card not present fraud - from 750,200 reported cases in 2012, to 1,437,832 reported cases in 2016[6]. Since it is not possible to know which method the criminal used to obtain the victim's payment card information there are no statistics on the distribution between different types of skimming.

RFID skimming compared to other types of skimming

In contrast to other types of skimming such as ATM skimming or hacking an online merchant's web page, RFID skimming requires little or no technical expertise. In order to execute ATM skimming, the criminal needs to custom build a device, then place that device inside an ATM and later pick up the device after the victims have used it. Hacking online merchants web pages requires substantial computer knowledge.

Myths

A common myth that is often mentioned by card issuers is that a criminal can only steal the maximum amount that is allowed for contactless purchases. This sum is usually between $30-$50 and is different for each country. This has been proven wrong in a test by British consumer magazine ''Which?''. In the test they successfully used wirelessly obtained payment card information to make an online purchase of over £3,000[7].

Methods for preventing RFID skimming

Metal foil

Shielding is possible by wrapping the payment card in aluminum foil. However aluminium foil tends to wear out quickly. Informal tests found that the shielding effect was not 100% effective, though it did very much reduce the maximum range for reading, from about 1.5 feet (50 cm) to 1–2 inches (3–5 cm)[8].

Permanent disabling of RFID functionality

RFID functionality can be disabled permanently by cutting internal wires; use of a microwave oven has also been reported successful, according to informal reports[9]. Cutting requires location of the internal wires, followed by cutting, drilling, or heating. Methods that visibly damage the card may lead to it being rejected as a payment method when presented to a retailer in the normal way.

RFID Blocking materials

There are several products you can buy which help stop your cards being skimmed. There are RFID blocking wallets, purses, sleeves, and cards. Wallets, purses and sleeves work by acting as a Faraday cage which creates a screen around your cards which stops electromagnetic fields interacting with the cards. The RFID blocking cards are the same shape and size as a regular credit card and is placed together with the cards it should protect. It contains a jamming device that is activated automatically when someone tries to scan the payment cards in its proximity[10].

References

  1. ^ "1 billion Visa contactless purchases made in last year". www.visaeurope.com. Retrieved 2019-01-06.
  2. ^ "NFC RFID Reader / Writer ACR122U ISO 14443A/B + Free Software in White: Amazon.co.uk: Beauty". www.amazon.co.uk. Retrieved 2019-01-06.
  3. ^ "EMV Card Reader - Apps on Google Play". play.google.com. Retrieved 2019-01-06.
  4. ^ Bachelor, Lisa (2015-07-23). "Contactless card fraud is too easy, says Which?". The Guardian. ISSN 0261-3077. Retrieved 2019-01-06.
  5. ^ PYMNTS (2017-01-18). "Card-Not-Present Fraud Picking Up In U.S." PYMNTS.com. Retrieved 2019-01-06.
  6. ^ "Financial Fraud Action UK - Fraud the Facts". www.financialfraudaction.org.uk. Retrieved 2019-01-06.
  7. ^ Bachelor, Lisa (2015-07-23). "Contactless card fraud is too easy, says Which?". The Guardian. ISSN 0261-3077. Retrieved 2019-01-06.
  8. ^ "Aluminum Foil Does Not Stop RFID". Omniscience is Bliss.
  9. ^ NTT (2013-09-15). "How to Disable 'Contactless Payment' on Your Debit Card". instructables circuits. Retrieved 2020-02-10.
  10. ^ "How SkimSafe Protects Your Identity and Card Details". YouTube. 2015-08-16. Retrieved 2020-02-10.