SBP issues guidelines to ensure cyber security

By
GEO NEWS

KARACHI: In wake of the recent ATM skimming incident, the State Bank of Pakistan (SBP) on Wednesday directed banks to develop infrastructure for EMV (Europay Mastercard Visa) Compliance and issue cards under it by June 30, 2018 to enhance cybersecurity.

In a press release issued by the SBP, it said: “It would be pertinent to mention here that debit cards with a magnetic strip on its back – that stores customer’s account details are particularly vulnerable to skimming and cloning,” adding, “debit cards complying with EMV (Europay Mastercard Visa) standards, featuring a chip and offering two factor authentication are now considered most effective countermeasure for card cloning through skimming globally.”

The SBP said that it has issued specific regulations for the security of payment cards and internet banking, under which banks are required to develop and implement comprehensive framework for risk assessment, implementation of controls and monitoring.

In the press release, the regulatory body said that it has noted with concern that customers’ information on debit cards of Habib Bank Limited was compromised by hackers through skimming to create its clones and were used to withdraw depositor’s money from various locations within and outside the country,

Since then SBP has been in contact with HBL management to ascertain the losses, returning of money to the affected customers and precautionary measures to limit the impact of this hacking activity.

HBL has taken several immediate actions to determine and limit the impact of such transactions on customers. Specifically, it blocked all identified debit cards that were suspected to be misused and quarantined the Automated Teller Machines (ATM) used in the hacking activity. Till today, 296 customers have confirmed the disputed transactions and the estimated damage assessment done to the concerned Bank is Rs10.2 million for their customers. HBL has also managed to start returning the money to depositors to the extent of their losses. Meanwhile, efforts are underway to determine losses to any other bank’s customers using HBL ATMs and take remedial measures.

ATM skimming — an illegal activity in which account details are stolen from the magnetic strip contained on the back of the debit card has been around for a while and such incidents have happened, sporadically, in Pakistan as well.