I would like to share my negative and frustrating experience with respect to fraudulent withdrawals from my Visa credit card. I was unjustly denied a refund for these withdrawals by HSBC Bank (Malta). I would like to prove the urgent need that banks require to take serious action to improve the security of the credit card system (based on EMV protocol) and to refund victims the claimed amounts they lost through fraudulent withdrawals and to acknowledge that these victims like myself were not negligent.
It all started in June 2011 at Palma de Mallorca when my wallet was stolen and within a few minutes €1,365 were fraudulently withdrawn from my Visa Chip and PIN card even though my PIN was kept secret and was nowhere inside my wallet. My claim was rejected by HSBC because they said that the withdrawals were a result of negligence from my side; I was to look after my PIN! Of course I never kept my PIN with my card and I had already confirmed all the facts relating to this incident under oath (with an affidavit)! A complaint was raised with MFSA who investigated the case and concluded that there was nothing irregular about the withdrawals and if I was dissatisfied with the outcome, recommended that I seek legal action. It must be noted that as part of the investigation, MFSA provided copies of the ATM withdrawals' logs supplied by HSBC, but MFSA do not have the expertise to interpret the technical data recorded in each ATM withdrawal log.
In the meantime I contacted Mike Bond, a computer security lab researcher at the University of Cambridge, to look into the case. I provided him with all the details and after over a year of research, on 10th September he and his Cambridge university team released to the media a paper entitled “Chip and Skim: cloning EMV cards with the pre-play attack”, which shows the unpredictable numbers vulnerability of the EMV system. Further details on this paper can be found on these links:
http://www.lightbluetouchpaper.org/2012/09/10/chip-and-skim-cloning-emv-cards-with-the-pre-play-attack/
http://www.bbc.com/news/technology-19559124
It was concluded that the ATM in Palma de Mallorca where my visa card was used was clearly deficient or may have been sabotaged with malware (i.e. it was infected with a computer worm or virus) mainly because of the following reasons:
1. The unpredictable numbers were predictable.
2. The withdrawals happened very quickly, quicker than an ATM would normally permit.
3. No typical daily withdrawal limit or fraud detection protection system for this rapid sequence of transactions was activated by the ATM.
EMV Co. (which manages, maintains and enhances the ATM card payment system) has recognised this problem and issued updated specs for which the affected ATM would fail testing. The following links refer to this matter:
http://www.emvco.com/download_agreement.aspx?id=702
http://www.emvco.com/download_agreement.aspx?id=744
The above clearly showed that in my case the ATM or the bank network was either already unreliable or there was a bank insider in Spain who had sabotaged the system. The €1,365 was withdrawn fraudulently and NOT because of negligence on my part; it is clear that the ATM/bank security system failed at Palma de Mallorca in June 2011. Further confirmation of the Palma de Mallorca ATM/bank security system problem comes from another case of a German bank, which has already refunded their client Ms Annette Luckey in a similar case of rapid withdrawals after a credit card theft in the same place.
In the light of the above developments, on 9 October I presented this information to HSBC’s Security and Fraud Department. Despite all this, after over a month, I received a terribly shocking and short answer that the bank's original decision remained unchanged, without giving any reason for rejecting my claim based on the new evidence established from the University of Cambridge research!
In view of this, I ask HSBC to seriously review its unreasonable decision, and refund me my losses (the withdrawals withdrawn fraudulently from my card). This matter has cost me time and money but the worst thing about it all is that the bank I trust with my money has not believed me. In the case of another rejection, the bank shall leave me no alternative but to do things in a different way. I have no intention of letting this case sleep, as I know I have nothing to hide. I know I am an honest person and I am not at fault and I intend to go all the way to prove this!
I would also like to ask the banks to take this matter more seriously and work hand in hand to improve the security of the EMV system and to consider carefully any fraud claims made by clients. Finally, I would be very pleased to help any victims of such phantom withdrawals, and ask them to contact me via the publisher/editor.
Alex Gambin