A message from your account managerPhishing/smishing, ransomware and credential harvesting remain the most common and damaging attack methods targeting payment systems. This month, we’ll explore each of these cybercrimes and look at actions you can take to potentially make your business less of a target. Trends in payments cybercrimeIdentity and access threats and fraud remain top cybersecurity concerns, with stolen credentials and phishing attacks driving the majority of breaches according to cybersecurity* experts. High transaction volumes and sensitive financial data make payment systems a prime target. Breaches can drive immediate financial loss and erode customer trust. Understanding the different attack types is an important first step in mitigating risks within your own business. Below, we review the most common threats. Ransomware Criminals use malicious software to infiltrate systems and steal payment data. Once inside, attackers may redirect transactions or exfiltrate sensitive information. Ransomware locks or steals access to files, systems or networks and demands payment for restoration. Phishing and smishing Attackers use deceptive emails or text messages that impersonate vendors to trick employees into sharing confidential data, including credentials, one-time codes, account numbers and passwords. These messages often appear legitimate (e.g., invoices or electronic faxes) but contain malicious links or attachments that can compromise systems. Skimming Digital skimming infects eCommerce websites with malicious code—often JavaScript (JS) “sniffers”—that is difficult to detect. Once embedded, these tools capture payment data during transactions without the merchant or customer’s knowledge. Physical skimming devices can also be placed on POS systems to steal card data. Invoice and vendor fraud Fraudsters impersonate legitimate vendors to alter payment details or request inflated payments, frequently bypassing standard verification controls in business-to-business and eCommerce environments. Fraudulent authorization testing Also known as enumeration attacks, these occur when automated bots send thousands of small authorization attempts—often just a few cents—using stolen card numbers to identify which accounts are still valid. Once validated, card data can be sold on the dark web or immediately used for fraudulent transactions. These attacks can also drive excessive transaction fees for merchants. Elavon notification If you believe your business, third-party processor or software provider has experienced a data security incident possibly impacting the risk of payment card data, notify Elavon Global Client Security. This helps ensure compliance with reporting requirements to the card brands (Visa, Mastercard, Discover, American Express, and others). Email Elavon Global Client Security at adcqueries-NA@elavon.com. Back to top |