Categories: FDIC

ATM and Card Authorization Systems

FIL-10-2014
April 2, 2014

ATM and Card Authorization Systems

Printable Format:

FIL-10-2014 – PDF (PDF Help)

Summary:

The FDIC, as a member of the Federal Financial Institutions Examination Council (FFIEC), is issuing the attached statement describing risks related to recent cyber-attacks on automated teller machines (ATMs) and card authorization systems that have resulted in large dollar frauds. These attacks are known as Unlimited Operations.

The FDIC expects financial institutions to take steps to address this threat by reviewing the adequacy of their controls over their information technology (IT) networks, card issuer authorization systems, systems that manage ATM parameters, and fraud detection and response processes.

Statement of Applicability to Institutions with Less than $1 Billion in Total Assets: This Financial Institution Letter (FIL) applies to all FDIC-supervised institutions.

Highlights:

  • Cyber-attacks on financial institutions for the purpose of gaining access to, and altering the settings on, ATM Web-based control panels used by small- to medium-sized institutions have increased.
  • Unlimited Operations are a category of ATM cash-out fraud in which criminals are able to extract funds beyond the cash balance in customer accounts or beyond other control limits typically applied to ATM withdrawals.
  • Financial institutions that issue debit, prepaid, or ATM cards may face a variety of risks from Unlimited Operations, including operational, reputation, fraud, liquidity, and capital risks.
  • Financial institutions should ensure that their risk management processes address the risks from these types of cyber-attacks consistent with the risk management guidance contained in the FFIEC IT Examination Handbook and applicable industry standards.
IR Press

Share
Published by
IR Press

Recent Posts

OCC Issues Annual Report for 2024

WASHINGTON—The Office of the Comptroller of the Currency (OCC) today published its 2024 Annual Report.…

2 days ago

OCC Announces Enforcement Actions for December 2024

WASHINGTON—The Office of the Comptroller of the Currency (OCC) today released enforcement actions taken against…

3 days ago

Treasury Maintains Pressure on Houthi Procurement and Financing Schemes

WASHINGTON — Today, the Department of the Treasury’s Office of Foreign Assets Control (OFAC) sanctioned…

4 days ago

Treasury Sanctions Georgian Ministry of Internal Affairs Officials for Brutality Against Protesters, Journalists, and Politicians

WASHINGTON — Today, the Department of the Treasury’s Office of Foreign Assets Control (OFAC) is…

4 days ago

Treasury Maintains Pressure on Iranian Shadow Fleet

WASHINGTON — Today, the United States Department of the Treasury is imposing sanctions on four…

4 days ago

Treasury Releases Report on the Uses, Opportunities, and Risks of Artificial Intelligence in Financial Services

WASHINGTON – Today, the U.S. Department of the Treasury (Treasury) released a report following the issuance of…

4 days ago