Translate

October 20, 2015

Is this your credit card? Hong Kong Monetary Authority presses banks over 1.25 million credit cards read by unauthorised parties

LAI YING-KITyingkit.lai@scmp.com

PUBLISHED : Tuesday, 20 October, 2015, 3:25am

UPDATED : Tuesday, 20 October, 2015, 9:27am

Credit cards issued by seven Hong Kong banks are affected. Photo: May Tse

The Hong Kong Monetary Authority is examining who should be held responsible for a security flaw that allowed customers' full names on contactless credit cards to be read by unauthorised parties.

Arthur Yuen Kwok-hang, a deputy chief executive at the authority, said yesterday the body had asked seven banks and two companies that provided cards for the banks to look into why some 1.25 million cards contained the cardholder's name.

"This is an issue we must identify," said Yuen. He noted the case involved complicated technical issues and the authority was still studying the cause and who should be held responsible.

Last week, the authority said some contactless credit cards issued by the seven banks contained a security flaw that allowed cardholders' names to be read by unauthorised parties using a mobile app when they made contactless payments.

The seven banks were Bank of China (Hong Kong), Bank of Communications Hong Kong Branch, China Citic Bank International, Dah Sing Bank, DBS Hong Kong, OCBC Wing Hang Bank and ICBC (Asia).

In total, 1.25 million cards were involved, with Bank of China (Hong Kong) accounting for 670,000 of them.

Yuen said the banks were working to replace the flawed cards.

He said that under safety requirements the authority established in 2012, contactless payment cards should not contain non-essential information or show a cardholder's full name.

Arthur Yuen Kwok-hang, a deputy chief executive at the authority, said the banks were working to replace the flawed cards. Photo: Jonathan Wong

However, Yuen stressed that the recent leak did not constitute a risk for standard contactless credit card transactions.

Since 2012, the authority has received one complaint about contactless credit card usage. The case involved unauthorised purchases at convenience stores made by a contactless payment card after it was reported lost.

There were reports that credit card numbers and expiry dates on some contactless cards could be read by a mobile app because the data was not encrypted.

Yuen said such a possibility existed, but to make purchases online, people had to provide a card number, its expiry date, and a verification code, which was physically printed on the card and not readable by card-reading devices.

Some online vendors allowed people to make purchases online by providing merely a card number and its expiry date. But Yuen said the authority in 2012 required card-issuing banks to notify cardholders by SMS when cards were used in this way.

"We checked its implementation in the wake of the latest incident, and the banks have been implementing this measure," Yuen said.

He said cardholders did not have to bear any losses caused by unauthorised purchases.

http://m.scmp.com/news/hong-kong/law-crime/article/1869858/data-leakage-hong-kong-monetary-authority-presses-banks