Blog article
See all stories ยป

An article relating to this blog post on Finextra:

Direct debit fraud at an all-time high; Bacs challenges figures

Over 97,000 Brits have fallen victim to criminals setting up fraudulent direct debits from their accounts, with this number set to escalate over the next three years, according to research from insura...


See article

Direct Debit fraud - the hidden threat

It is commonly accepted that criminals react very quickly to newly-introduced security measures. Perhaps it is not surprising that as new fraud prevention technologies such as Chip and PIN and two-factor authentication have become the norm, fraudsters are already moving to the next perceived loophole - direct debits. Typically this is, as discussed in the report, a fraud of "misuse of facility": using someone else's bank account to pay the fraudster's bill. The telecoms industry provides a prime example of the challenges around direct debit fraud. Criminals set up unauthorised direct debits on third-party bank accounts or by using stolen and/or made-up account details and walk out of high-street shops with expensive smartphones and no intention of paying the ongoing subscription.

From our research many corporates still report direct debit fraud as theft and therefore report it to the police instead of informing their bank or a clearinghouse such as Bacs. It is therefore not surprising that these organisations don't get to see the true picture. What businesses have to bear in mind, however, is that, as cheques decline and efficiency becomes paramount in this new age of austerity, there is a general drive in both the private and public sector to move more and more payments to Direct Debit. A propotion of these will be fraudsters posing as legitimate customers and this report provides a first estimate of this fraction.

It is heartening to see a business talking openly about the problems of preventing fraud. Only by facing up to the challenges, including what measures could be applied to manage the problem, can the payments industry start to take control. The key is further verification of the data provided. Direct Debit originators should check the account numbers appear to be valid, but best practice is to confirm the link to the owner of the account, authenticate the prospective consumer and, ideally, his or her address.

Fraud considerations, especially in today's financial climate, need to be top of the agenda for financial institutions and corporates. In order to prevent a rise in direct debit fraud, companies need to adopt the relevant data validation tools to verify a customer's account at the point of entry. Connecting an individual's identity to their bank account and address is one solution; only by linking these three pieces of information can corporates really be sure of their consumer information, and more importantly the source or destination of their customer's funds. Preventing fraud is like repairing a burst pipe - it is only when all the holes have been plugged that there will be no leakage.

12821

Comments: (2)

Bob Lyddon
Bob Lyddon - Lyddon Consulting Services - Thames Ditton 26 November, 2010, 17:12Be the first to give this comment the thumbs up 0 likes

Hi Jonathan - how would you characterise the SEPA Direct Debit scheme in this regard, where the mandate is created by the creditor (the originator) through its scheme-adhering bank within the EU, and all current accounts in the eurozone are now reachable as debit accounts by EU Directive 924/2009?

A Finextra member
A Finextra member 08 December, 2010, 15:23Be the first to give this comment the thumbs up 0 likes

Bob, In my view the SEPA Direct Debit Scheme also exhibits this potential loophol.

The creditor can capture malicious details from their customer (the fraudster), resulting in an fraudulent direct debit being initiated by the bank. Without the capability to verify the link between the creditor's customer and his/her bank account, banks will be as powerless as their business customers to prevent or identify this type of fraud until the protection of the Payment Services Directive or Direct Debit Guarantee is exercised by the victim, the real owner of the account.

Without this sorts of safeguard, based on reliable data, there is no impediment for this type of fraud.

Now hiring