Skip to content

Invest1 publisher3 min readPublished

Fraudsters are unfreezing stolen cards through Fiserv's automated line, four credit unions say

Fiserv's lawyers told Florida credit union FiCare that its automated phone system can lift a fraud freeze on a card before any human hears the call. Fiserv says FiCare passed on extra security it had available, so the open question for the more than 3,330 credit unions it serves is whether switching on passcodes closes the gap.

The Investor · Invest desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Photograph accompanying Fraudsters are unfreezing stolen cards through Fiserv's automated line, four credit unions say
Photo: americanbanker.com

What happened

  • Three other credit unions told colleagues on an email list that fraudsters posing as members were calling Fiserv's card services to get fraud holds lifted or charges approved.
  • In the one call the court record documents, the agent asked only for the caller's name, reviewed three transactions the caller called valid, and closed the case.
  • Fiserv's counsel offered on Sept. 24 to switch passcodes on for FiCare "promptly," and FiCare asked for them less than two hours later.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • exposure Fiserv credit unions without one-time passcodes rely on the same EnFact checks FiCare did, where a Social Security number can replace the case number that only the alert supplies.
  • decision Fiserv's defense makes passcodes the client's choice, so each of its credit unions without them now has to decide whether to ask, as FiCare did within two hours of the offer.
  • contradiction Fiserv offers passcodes as the fix, yet its filings put them at the contact center, and EnFact sends calls there only after a check fails, so a caller who passes EnFact may never meet one.

Fiserv's email to FiCare lists three checks on EnFact's automated callback line [6]. The call must come from the cardholder's phone number, the caller must have dialed the callback number in the alert, and the caller must enter the alert's case number [6]. If all three pass, "the card will be unfrozen," the email said [6]. EnFact will also take the cardholder's full Social Security number in place of the case number [7]. The case number and the callback number both arrive in the alert, and the callback number can differ from one case to the next [5]. A Social Security number has nothing to do with the alert.

In the one call the court record documents, the caller had the right caller ID, Social Security number, ZIP code, card security code and expiration date [9]. The agent asked for a name, went over three transactions and closed the case [10]. FiCare asked whether closing a case with no case number and no extra verification was standard. Fiserv replied that the caller had passed the automated checks, so only the name was needed [11]. Court records do not show which automated systems that call went through [12].

Fiserv serves roughly 10,000 financial institutions, including more than 3,330 credit unions [17], so credit unions make up about a third of its client list [1]. Four of them are in the record. FiCare's filings say fraudsters passed Fiserv's automated checks to reactivate stolen cards [3]. Three more credit unions described fraudsters posing as members on Fiserv's card-services line, in emails FiCare attached to its filings [4]. Four out of 3,330 is about 0.12% [2], and that counts only the credit unions writing to one email list.

The dispute sits inside a monthslong lawsuit over cyberattacks that compromised credit union members' online banking accounts [1]. Fiserv's position is about configuration. It says FiCare had additional security measures available and passed on them [13]. Its counsel offered on Sept. 24 to switch passcodes on "promptly," and FiCare asked for them less than two hours later [14]. On that reading the weakness belongs to the clients who never asked, or rather, to a setting that was off at FiCare until it did ask. FiCare's lawyer takes the other side and wrote that the automated system "appears to remain insecure" even with passcodes [15]. A third reading spreads the problem across the sector, because banks and credit unions across the industry use automated processes to lift fraud holds [2].

I think FiCare's reading has more support in Fiserv's own description than Fiserv's filings concede. Those filings describe a passcode option at the contact center [16]. The email sends a call to the contact center only when one of EnFact's three checks fails [8]. A caller who matches the phone number, dials the right callback line and types a Social Security number gets the card unfrozen at the first stage [6] [7], before reaching any step a passcode would guard. At the contact center itself, a credit union without one-time passcodes relies on what Fiserv's email called "tokens related to the cardholder's account" [19]. The counter-case is that the callback number can change by case [5], so a caller who never saw the alert may not reach the right line at all. Fiserv's remedy so far works one client at a time: passcodes switched on for FiCare when it asked [14].

The view is wrong if credit unions already running passcodes turn out to have none of these calls, or if Fiserv shows the passcode also applies on EnFact's automated path. Fiserv did not immediately respond on the record to a request for comment [18].

What to watch

  • Whether credit unions that already run one-time passcodes on Fiserv report the same reactivated-card calls.
  • Whether Fiserv drops or restricts the Social Security number as a substitute for the case number on EnFact's automated line.
  • How the Florida court handles FiCare's request, and whether it treats passcodes as Fiserv's fix or the client's responsibility.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories