Showing posts with label Credit Card Safety. Show all posts
Showing posts with label Credit Card Safety. Show all posts

Credit Card Information - Fetches Big Money

While economies went into a tailspin in 2009, credit card information, wrongfully extracted by hackers, commanded a huge premium in the grey market — more than double the price they did a year earlier. 

In some cases, data encrypted on the magnetic strip of credit cards were being sold at six times more. The username and password of sites like PayPal that accountholders can withdraw cash from, were up by $600 per account. 

On the other hand, bank credentials — account numbers, net banking transaction access codes and personal account passwords — appear to have become a little cheaper over the past one year. So are e-mail passwords over the past one year. 

Card Protection Program FAQs

For instance, leading web security firm Symantec says credit card information — along with the card verification value (CVV) — was $30 per card during 2009 against $12 in 2008. CVV is the three-digit number on the opposite side of the card and is a must for making online transactions. 

Data encrypted on the magnetic strip of a credit card, referred to as credit card dumps, contains the primary account number and the expiration date as well as card-holder’s name. Each credit card issuer has its own standards for encoding this information. The highest price for such information was $140 per card in 2009 against $25 per card in the previous year. 

User name and password of sites, including PayPal, referred to as cash-out services, were selling at 50% of the total value of the cash that could be siphoned off from a single account during 2008. During 2009, the prices increased $600 flat. 
Bank account information, however, dropped from $1,000 in 2008 to $850 in 2009. Over the same period, e-mail accounts sold at $20 on the higher side during 2009 against $30 in the previous year. Credit card info and bank accounts still top advertised items in the underground economy. However, credit card dumps saw a marked increase in advertisements.

Popularly called underground economy, there are a set of hackers who deploy various malicious methods to extract sensitive data from unsuspecting PC users. Having extracted a sizeable volume, they advertise on various sites to sell them. The potential of financial gain from these data determines the price for any set of information. 

There is another set of hackers who use such stolen information to extract money,  The ones that steal the information may not always want to use them and, therefore, remain unidentified. Hence, they are satisfied with selling them in the underground economy. The ones that buy them are capable or intend to take more risks than the ones that steal the information... Interestingly, there are two distinct sets of people. 

Prices of credit card information have gone up because credit limits offered were raised over the past one year. Prices of bank account information have declined because it is becoming increasingly difficult to use bank information to siphon off funds. 

Card Protection Program India

Prices are also dependent on factors like average credit limits on cards in specific countries. For example, credit card information in the US will fetch higher prices than those in India or Bangladesh. In contrast, bank account or debit card information from countries like India will fetch more money than in the US since Indians have a propensity to save and, therefore, likely to have more funds in their bank accounts than an average US citizen.

LIC Credit Card and Credit Card Protection program


LIC credit card holders can now report loss of any of their cards from anywhere in the world to a 24-hour helpline launched by LIC Cards Services. 

LIC Cards Services Ltd has launched Card Protection Plan for its credit card customers in partnership with CPP Assistance Services which will safeguards all of the LIC cardholder's payment cards - credit, debit and ATM cards. 

The members can also be able to register their non-financial cards such as store cards, loyalty and membership cards. 

Credit Card Security

Besides these, customers will be able to retrieve important details on lost/stolen documents like passport, PAN and driving license also 


To avail the new service, customers would need to purchase a membership plan offered by LIC and register their cards with CPP.

Credit Card Information for Sale


While the global economic turmoil is forcing Governments to initiate measures to arrest further decline in growth rates, cyber crooks operating in the underground economy seem to be cashing in on the opportunity.

Wondering how? With shopping and banking transactions occurring online, password stealing has, for instance, become a common cyber crime. McAfee Avert Labs has seen the count of password stealing malware variants increase by nearly 400 per cent during 2007-08.

Symantec’s Report on the Underground Economy reveals that the most frequently advertised item on underground economy servers are bank account credentials (which consist of account numbers and authentication information) accounting for 18 per cent of goods and services available for sale.

The large supply of bank account credentials may be due to a shift towards online banking.

Forty four per cent of Internet users perform some degree of Internet banking in the US, it is higher at 67 per cent in Canada. It has just caught on in India. According to the report, the advertised prices for bank account credentials ranged from $10 to $1,000 (between July 2007-June 2008), with prices depending on the amount of funds available, the location and type of account.

The second most common advertised item was credit card numbers accompanied by CVV2 numbers, accounting for 16 per cent of the sale of all advertised goods and services. (Merchants at many online sites require the CVV2 number as part of their authorisation process and the number of sites requiring this authentication is increasing.)

The Report said credit cards with CVV2 numbers were typically sold in bulk, with packages ranging in size from 5 to 500. The advertised prices of these ranged between $0.50 and $12.

The third most common item advertised for sale on underground economy servers was credit cards, accounting for 13 per cent of all advertised goods during the reporting period. Symantec perceives credit cards as not being as popular as bank account credentials or credit card numbers possibly because these are difficult to exploit due to the time-sensitive nature of the stolen cards and increased security measures taken by merchants.

Credit card prices observed on the underground economy servers ranged from $0.10 to $25 per card number. Symantec estimates the value of the total advertised goods on observed underground economy servers at over $276 million during the said period.

While law enforcement agencies strive to arrest and indict those involved in frauds and identity theft, the global nature of these criminal enterprises is making it increasingly difficult to locate their operations and shut them down.

This is just the tip of the iceberg. Cyber criminals are on the prowl, looking for newer ways to make money. So, keep your identity and wallet safe by adopting security safeguards.

back to Credit Card Security articles

Register your Credit card for Online shopping


Are you planning to shop online in the near future? Or is there any other online transaction, involving the use of plastic money, high on your agenda?

If yes, better get registered with your bank, otherwise you won’t be able to use your credit or debit card online just after a week’s time. For, the RBI has made it mandatory for all online transactions to have an ‘extra’ level of authentication from August 1, 2009 onwards. And some banks have already started complying with this mandate.

Although lots of ecommerce players are concerned about losing their business in the short run, as they believe that many shoppers, who are still not aware about the RBI mandate, may simply ditch the buying decision at the checkout process, bankers view this as one more step towards moving closer towards a fraud-proof world of online transactions.

“This is just to add an additional layer of security for online transactions. This requires that a password in addition to information available on the credit card itself be given to ensure that it is the card holder himself who is authorizing the payment,” says Harsh Roongta, CEO, ApnaPaisa Pvt Ltd, adding, “typically even as you are shopping, the payment gateway will allow you to verify your credit card under the ‘Verified by Visa’ or ‘Verified by Mastercard’ programme by providing details that are not stored on the credit card.”

Thus, anyone shopping online from August 1 onwards will be required to first register one’s existing card for this service. One can do this either by visiting the website of one’s respective bank or by choosing to accept the registration process on the merchant websites. In case of the former, a customer can create a password and a shared secret instantly. However, for getting registered while shopping online, you need to select the goods or services you want from a Verified by Visa/ MasterCard SecureCode online store and proceed to the payment page. There you will have to enter your card number and the online store will connect with your bank to check whether your card is enrolled for this service.

The users who are registered for this service will be asked to put their password, while the users who are not registered for this service will be prompted to activate the same by creating the password and shared secret on the merchant website itself. Once the identity is verified, the transaction will be completed. Based on the authentication provided by the issuer, the transaction will be processed and the user will get a confirmation.

“This service, thus, assures cardholders of additional security while shopping online using their existing Visa or MasterCard credit card. It confirms the cardholder’s identity through a simple check process when he/she makes online purchases,” says an SBI Card spokesperson.

In other words, this registration will make the online transactions more secure as in order to process the payments, the merchant website will
ask for the password to be input. And transactions will not be processed without the password. Thus, even if your card gets stolen, one won’t be able to make any online purchase in the absence of the password.

“Incidentally, even for shopping transactions offline where the card is ‘not present’ will now require that the bank send an SMS to the credit card holder for amounts larger than Rs 5,000,” says Roongta.

On the flip side, however, the service of card authentication will only be eligible/applicable to merchant websites who are also compliant with this service. This means that this authentication will not be required for transacting on portals which are not compliant with this service or those based outside India. This has left many big ecommerce players worried as they believe that this may affect their business, at least in the short run. Bankers, however, think otherwise and say that online transactions will not be affected much as the customers would, sooner or later, be aware that this is for the security of their own card and hence for their own benefit.

Credit Card Safety one more measure


If you frequently use your credit/debit card to make online payments and are worried about the security of the transactions, relax. Another safety net is coming.

From August 1, a new authentication system will be in place to provide extra safety to your online card transactions. The Reserve Bank of India has made it mandatory for all online card transactions to have an extra level of authentication.

For Visa Card users, for example, the new rule would mean they will have to register under the ‘Verified by Visa’ service being offered by their banks.

“ ‘Verified by Visa’ is a new way to add safety when you buy online. Adding a password to your Visa card, ‘Verified by Visa’ ensures that only you can use your Visa card online,” says a note on the portal of Visa.

The card-holders need to set up their ‘Verified by Visa’ password and activate their cards through the issuer.

Pop-up message

The extra level of authentication works in the form of a pop-up message during an online transaction that asks for the password.

“Currently, the safety parameters adopted by the banks include the card number, date of birth and the Card Verification Value (CVV) number printed on the back of the card. In some cases, the date of birth is not mandatory, making the transaction insecure,” explained an official of HDFC Bank.

The new systemwould make unauthorised transactions nearly impossible. “Many customers are not even aware that the CVV number on the cards should be erased to prevent misuse,” explained a senior official of Andhra Bank.

RBI's Step to Check Credit Card Fraud


From August 1, you need not think twice before letting your credit card out of sight at a restaurant, petrol pump or any other merchant establishment. The details printed on your card including the card number, expiry date and three-digit card security code (popularly known as the CVV) will not be enough to make fraudulent online transactions.

A RBI directive has ensured that from August, credit and debit card-issuing banks must provide for additional authentication of information over and above what is visible on the physical card. In other words, the cardholder must key in an extra security code or some other data to complete a online transactions.

This consumer-friendly instruction, issued by the RBI on February 18, also mandates a system of online alerts to the cardholder for all `card not present' transactions that exceed Rs 5,000. The circular adds that banks would be penalised for non-adherance to the directive under the Payment and Settlement Systems Act 2007.

In an email response to TOI, RBI though specifies, "Banks are free to decide on the technology they wish to use to fall in line with these instructions.'' On their part, banks have been beefing up their online security. Virtual cards, which have been around for a while, are a secure option offered by the likes of HDFC Bank, ICICI Bank and Kotak Mahindra Bank. HDFC's NetSafe, for one, creates a code that can be used for one-time transaction. "It is a limited period validity number,'' says Sanjeev Patel, EVP and head, direct banking channels, HDFC Bank.

Virtual cards create a code separate from your CVV number so you don't have to key it in on the merchant website. Any unused amount from the card is credited back to the credit or debit card account.

Banks also offer increased security via MasterCard's Securecode and Visa's Verified by Visa, which offer personalised passwords. T V Seshadri, vice-president and country general manager, South Asia, MasterCard, says, "Much like the authentication process required for payment card use at ATMs, SecureCode requires cardholders to enter their personal code in an online window on their PC before a transaction can be processed. Even if someone knows their credit or debit card number, the purchase cannot be completed without their SecureCode at a participating merchant.''

But these initiatives can work only if the cardholder is prompted to enter the code by the merchant site. Says Seshadri, "The card-issuing bank, the retailer and the retailer's acquiring bank will all have to participate. Even if one of these entities does not participate, the cardholder is not prompted to enter the SecureCode.'' Seshadri, though, adds that a number of banks in the country no longer allow their cardholders to transact on e-commerce sites without entering such the code.

Credit Card Frauds to be checked by RBI ruling.


You need not think twice before letting your credit card out of sight at a restaurant, petrol pump or any other merchant establishments from August 1st.The details printed on your card including the card number, expiry date and three-digit card security code (popularly known as the CVV) will not be enough to make fraudulent online transactions.

A RBI directive has ensured that from August, credit and debit card-issuing banks must provide for additional authentication of information over and above what is visible on the physical card. In other words, the cardholder must key in an extra security code or some other data to complete a online transaction.

This consumer-friendly instruction, issued by the RBI on February 18, also mandates a system of online alerts to the cardholder for all `card not present' transactions that exceed Rs 5,000. The circular adds that banks would be penalised for non-adherance to the directive under the Payment and Settlement Systems Act 2007.

In an email response to TOI, RBI though specifies, "Banks are free to decide on the technology they wish to use to fall in line with these instructions.'' On their part, banks have been beefing up their online security. Virtual cards, which have been around for a while, are a secure option offered by the likes of HDFC Bank, ICICI Bank and Kotak Mahindra Bank. HDFC Bank's NetSafe, for one, creates a code that can be used for one-time transaction. "It is a limited period validity number,'' says Sanjeev Patel, EVP and head, direct banking channels, HDFC Bank.

Virtual cards create a code separate from your CVV number so you don't have to key it in on the merchant website. Any unused amount from the card is credited back to the credit or debit card account.

Banks also offer increased security via Master card's Securecode and Visa's Verified by Visa, which offer personalised passwords. T V Seshadri, vice-president and country general manager, South Asia, MasterCard, says, "Much like the authentication process required for payment card use at ATMs, SecureCode requires cardholders to enter their personal code in an online window on their PC before a transaction can be processed. Even if someone knows their credit or debit card number, the purchase cannot be completed without their SecureCode at a participating merchant.''

But these initiatives can work only if the cardholder is prompted to enter the code by the merchant site. Says Seshadri, "The card-issuing bank, the retailer and the retailer's acquiring bank will all have to participate. Even if one of these entities does not participate, the cardholder is not prompted to enter the SecureCode.'' Seshadri, though, adds that a number of banks in the country no longer allow their cardholders to transact on e-commerce sites without entering such the code

Credit Cards during foreign travel - Points one must take care


While credit cards are accepted at many million locations worldwide, there still may be times when cash is your only payment option. However, you should be cautious of carrying too much cash around. Despite the rather ingenious methods people have created, such as hiding cash throughout their luggage or on their bodies, cash can nevertheless be lost or stolen. And if it is, it cannot be replaced, like a card. Carrying a credit or debit card is, therefore, much safer than carrying cash or travellers cheques.

If you hold a MasterCard, for instance, you would have the protection of the MasterCard “zero liability” policy. To qualify for zero liability protection, you must meet certain conditions including having exercised vigilant care in safeguarding your card and immediately notifying your issuing bank of the loss, theft or unauthorised use of your card.

This apart here is a simple list of tips for travellers using their credit or debit cards abroad:

* Before you leave, check the expiry date and credit limit of your card. You don’t want to arrive at your destination and find that your card has either expired or reached its limit. Also, if you find that you’re near your limit, you might be able to increase it through your bank.

* Contact the bank that issued your card and let them know where and when you’ll be travelling. This is strongly advised so that the bank is aware that overseas transactions will be made. The unfamiliar spending patterns could cause your bank to suspect that your card is being used fraudulently and thus delay your card purchase approvals.

* While you have your bank on the phone, ask if you need to change your PIN number so that it will work in the country you’re visiting, as some foreign ATMs often only accept four-digit PIN numbers. If it turns out you that you do need to change it, ask how to go about doing so.

* Make several photocopies of the front and the back of the credit and debit cards that you’ll be taking with you on your trip. Leave one copy with a relative or friend back home and carry the other with you. Also write down your bank’s emergency contact information. This way, if your card is lost or stolen, you can quickly provide your bank with all the necessary information needed to have it cancelled. Better still, contact MasterCard Global Services directly who will put you in touch with your bank.

* When making purchases, ask whether your card will be charged in the foreign currency or in your country’s currency. An increasing number of merchants are equipped to convert the cost of a transaction to the cardholder’s own currency, but they often will impose an additional service fee or use an exchange rate inferior to that used by the credit card companies.

* Consider taking more than one credit/debit card with you. You’ll want to keep them in different places. This way, if one is lost or stolen, you’ll have a backup.

* If your card is lost or stolen, you can cancel it and the money remains in your account, provided whoever stole your card didn’t use it before you were able to phone your bank and cancel the card. With cash, if it’s gone, it’s gone for good and cannot be traced.

* If you use a credit card to book a hotel or hire a car, the company may put a hold on your account for the total amount of your expected bill. This could be an inconvenience, especially if it ties up your entire credit card limit. Again, a second credit card might come in handy. Do make sure, though, that the company removes this hold once you’ve paid the bill.

* Some banks offer you free travel insurance if you pay for your overseas flights with your credit card. This means that you are covered in the unfortunate event of a medical emergency, trip cancellation or baggage losses.

It is advisable that you double check what your insurance covers and whether you will need additional top-up coverage, as most banks offer a basic travel insurance package.

It is of little wonder, then, that credit and debit cards have come to be regarded as the best way to pay for expenses while travelling abroad.

back to Credit Card Security articles

Credit Card Operations of banks- RBI Guidelines I


Pursuant to the announcement made in the Annual Policy Statement 2004-05, the Reserve Bank of India had constituted a Working Group on Regulatory Mechanism for Cards. The Group has suggested various regulatory measures aimed at encouraging growth of credit cards in a safe, secure and efficient manner as well as to ensure that the rules, regulations, standards and practices of the card issuing banks are in alignment with the best customer practices. The following guidelines on credit card operations of banks have been framed based on the recommendations of the Group as also the feedback received from the members of the public, card issuing banks and others. All the credit card issuing banks / NBFCs should implement these guidelines immediately.

Each bank / NBFC must have a well documented policy and a Fair Practices Code for credit card operations. In March 2005, the IBA released a Fair Practices Code for credit card operations which could be adopted by banks / NBFCs. The bank / NBFC's Fair Practice Code should, at a minimum, incorporate the relevant guidelines contained in this circular. Banks / NBFCs should widely disseminate the contents thereof including through their websites, at the latest by November 30, 2005.

Guidelines for Implementation
1. Issue of cards

a. Banks / NBFCs should independently assess the credit risk while issuing cards to persons, specially to students and others with no independent financial means. Add-on cards i.e. those that are subsidiary to the principal card, may be issued with the clear understanding that the liability will be that of the principal cardholder.

b. As holding several credit cards enhances the total credit available to any consumer, banks / NBFCs should assess the credit limit for a credit card customer having regard to the limits enjoyed by the cardholder from other banks on the basis of self declaration/ credit information.

c. The card issuing banks / NBFCs would be solely responsible for fulfillment of all KYC requirements, even where DSAs / DMAs or other agents solicit business on their behalf.

d. While issuing cards, the terms and conditions for issue and usage of a credit card should be mentioned in clear and simple language (preferably in English, Hindi and the local language) comprehensible to a card user. The Most Important Terms and Conditions (MITCs) termed as standard set of conditions, as given in the Appendix, should be highlighted and advertised/ sent separately to the prospective customer/ customers at all the stages i.e. during marketing, at the time of application, at the acceptance stage (welcome kit) and in important subsequent communications.

2. Interest rates and other charges

a. Card issuers should ensure that there is no delay in dispatching bills and the customer has sufficient number of days (at least one fortnight) for making payment before the interest starts getting charged.

b. Card issuers should quote annualized percentage rates (APR) on card products (separately for retail purchase and for cash advance, if different). The method of calculation of APR should be given with a couple of examples for better comprehension. The APR charged and the annual fee should be shown with equal prominence. The late payment charges, including the method of calculation of such charges and the number of days, should be prominently indicated. The manner in which the outstanding unpaid amount will be included for calculation of interest should also be specifically shown with prominence in all monthly statements. Even where the minimum amount indicated to keep the card valid has been paid, it should be indicated in bold letters that the interest will be charged on the amount due after the due date of payment. These aspects may be shown in the Welcome Kit in addition to being shown in the monthly statement.

c. The bank / NBFC should not levy any charge that was not explicitly indicated to the credit card holder at the time of issue of the card and getting his / her consent. However, this would not be applicable to charges like service taxes, etc. which may subsequently be levied by the Government or any other statutory authority.

d. The terms and conditions for payment of credit card dues, including the minimum payment due, should be stipulated so as to ensure that there is no negative amortization.

e. Changes in charges (other than interest) may be made only with prospective effect giving notice of at least one month. If a credit card holder desires to surrender his credit card on account of any change in credit card charges to his disadvantage, he may be permitted to do so without the bank levying any extra charge for such closure.

3. Wrongful billing

a. The card issuing bank / NBFC should ensure that wrong bills are not raised and issued to customers. In case, a customer protests any bill, the bank / NBFC should provide explanation and, if necessary, documentary evidence to the customer within a maximum period of sixty days with a spirit to amicably redress the grievances.

b. To obviate frequent complaints of delayed billing, the credit card issuing bank / NBFC may consider providing bills and statements of accounts online, with suitable security built therefor.

4. Use of DSAs / DMAs and other agents

a. When banks / NBFCs outsource the various credit card operations, they have to be extremely careful that the appointment of such service providers do not compromise with the quality of the customer service and the bank / NBFC’s ability to manage credit, liquidity and operational risks. In the choice of the service provider, the bank / NBFCs have to be guided by the need to ensure confidentiality of the customer’s records, respect customer privacy, and adhere to fair practices in debt collection.

b. The Code of Conduct for Direct Sales Agents (DSAs) formulated by the Indian Banks’ Association (IBA) could be used by banks / NBFCs in formulating their own codes for the purpose. The bank / NBFC should ensure that the DSAs engaged by them for marketing their credit card products scrupulously adhere to the bank / NBFC’s own Code of Conduct for credit card operations which should be displayed on the bank / NBFC’s website and be available easily to any credit card holder.

c. The bank / NBFC should have a system of random checks and mystery shopping to ensure that their agents have been properly briefed and trained in order to handle with care and caution their responsibilities, particularly in the aspects included in these guidelines like soliciting customers, hours for calling, privacy of customer information, conveying the correct terms and conditions of the product on offer, etc.

back to RBI guidelines on Credit Card

What's the first thing you should do if you lose your credit card?


Just call up the bank’s 24 hour call centre and deactivate the card. This should
take precedence even over your attempt to track your wallet in the lost trail.

This is because very few banks in India offer protection against fraudulent use of credit cards. Of course, you can breathe a little easy if your bank insures your lost card from any misuse.

Standard Chartered Bank, for instance, has tied up with Tata AIG General Insurance Company to launch the ‘Plus Extended Protection Plan’ last week. This product, which has to be bought separately, will cover the card customers from any possible fraudulent use of the cards prior to reporting the loss. “We receive several lost card reports in a month. The product will ensure protection to our customers against any fraudulent use,” said RL Prasad, general manager, Credit Cards and Personal loans, Standard Chartered Bank.

The insurance cover will reimburse (up to Rs 50,000) per fraudulent transaction up to 12 hours prior to the customer reporting the loss to the bank. Also, the bank has extended this cover to all debit and credit cards. Similarly, even ABN Amro Bank offers this cover with a total coverage of Rs 2,000-Rs 5,000 at a monthly premium of Rs 100.
In case of SBI Cards, the credit card company caps the liability to a maximum of Rs 1,000 for non-gold cards once it receives a proper notification of the loss by the customer. The gold card customers enjoy zero liability once they notify the bank authorities.

Among the other leading credit card players, Citibank is still mulling the idea of offering a similar protection. ICICI Bank, however, doesn’t offer any such cover. Says Sachin Khandelwal, Head — Cards Product Group of ICICI Bank: “This cover is not very useful. We send mobile alerts whenever customers swipe in excess of Rs 2,000. That would help them keep a tab on all cards.”

HDFC Bank offers an insurance cover, which covers the customer from fraudulent transactions for up to 24 hours. Moreover, the cover comes free of cost. But you have to also file an FIR to hedge against these frauds. “For claiming insurance on any fraudulent transaction, you have to file an FIR with the police. Then you have to furnish the FIR along with credit card details to file a claim. Once the claim gets validated, it compensates for the fraudulent transaction, says Parag Rao, executive vice president — product, portfolio management and cards, HDFC Bank.
So, if the credit card company doesn’t offer any protection, then it holds the customer liable for any fraudulent transaction. You have to report the loss of the card immediately if you want to play safe. Once the customer communicates to the bank in telephone/writing the customer continues to enjoy zero liability on their lost cards. This means you don’t have pay a single penny if your credit card is stolen and has been subjected to fraudulent practices.

In the US, the maximum liability on the customer is capped at $50 per credit card. As the days pass by, this liability increases to $100 for the second day and $500 for the third day. If you don’t file a complaint with the bank for more than 60 days, then the customer is liable for every fraudulent transaction. However, the possibility of the customer being unaware of the loss for 2 months is very less, say experts.

This is an optional cover. But if your bank offers the cover to protect the lost card against fraudulent use, it is definitely not a bad idea. You will be spending a monthly amount of Rs 100 for saving a credit limit of may be a lakh from being misused. But most big banks are yet to offer this insurance cover. If it still pops out of the wallet, make a quick call and deactivate it. Follow the call with a written complaint and post it to the credit card company.

Changing face of consumer credit


BORROWERS beware! Big brother is watching you. That is the message sent out by the Credit Information Companies (Regulation) Bill passed by the Rajya Sabha without much fanfare this May. The passage of the Bill, which will become the Credit Information Act once the President blesses it, ushers in a new world where everybody that matters may know yours name.


The Credit Information Bill not only makes it lawful for all credit providers in the country to pool and share information on borrowers and their transactions without their consent, but actually obliges them to do so.


Credit providers which fall within the ambit of the Bill include all banks and non-banking financial companies that offer any form of collateralised or non-secured credit facility. The only form of credit provider not explicitly covered by the Bill is the pawn-broker.


The stated objective behind the official launching of a cartel-like cooperation among otherwise competitive financial institutions is to lower the burden of non-performing assets (NPAs) in the country by facilitating better credit risk managementthrough information sharing.


The credit information sharing process works as follows:

Each institutional credit provider electronically reports to a central database hosted by a credit information company called a "credit bureau" (that is, the Big Brother). Personal details of borrowers, their borrowings, repayment history and delinquency status are all reported on a monthly basis.


In return for reporting their internal data on customers to the credit bureau, each credit provider receives instantaneous electronic access to the comprehensive borrowing history of all their present and prospective customers.


All the information contained in the credit file is fed into a mathematical model as input criteria, and a risk score indicating the customer's creditworthiness is calculated. The risk score is then used as the basis for determining whether the customer is approved for the loan and under which terms and conditions.


The credit information sharing process in India was kicked off in a controlled environment through the establishment of the country's first credit bureau, Credit Information Bureau (India) Ltd, (Cibil) in 2000.


The scope of credit information sharing, which till recently was limited to institutional defaulters for the most part, has now been expanded to encompass individual consumers as well. It is no longer confined to defaulters, but also includes those consumers who meet their repayment obligations promptly and keep their credit accounts in good standing.


At the last count, about 30 leading financial institutions in the country were reporting customer credit data to the central database housed in Cibil, whose size has grown rapidly to about 20 million records. More than 100 credit providers in the country have accepted membership of Cibil and can be expected to start reaping the benefits of credit data-sharing very soon.


With the passage of the Credit Information Bill in Parliament, one can also expect to see a few more credit bureaus, like Cibil, enter the fray in the near future, possibly in partnership with other American credit bureaus such as Experian and Equifax.


In the US, from where this concept of credit bureaus is borrowed, credit data sharing is underpinned by a fairly robust, responsive and responsible regulatory mechanism which, in addition to serving the business needs of credit providers, also protects the interests of bona fide credit seekers, defaulters under true hardship and consumers at large.


The regulations, which are frequently debated in the House and updated to reflect the latest business practices, take a comprehensive view of the lending industry and its complexities by considering in microscopic detail all activities carried out by each player in every phase of the credit lifecycle.


The credit regulations lay down in great detail the code of conduct to follow for each and every activity in the credit lifecycle. The responsibility of enforcing the regulations has been entrusted to the Federal Trade Commission (FTC), an umbrella organisation that promotes fair business practices.


The FTC, which uses the quote from Victor Hugo to remind itself of the loftiness of its purpose, plays an active role as a conduit for handling consumer issues and as an ombudsman in ensuring that an equitable balance is struck between conflicting interests.


Here are a few highlights from the American credit regulations, violations of which entail hefty financial damage:

  • Consumer data must be held securely and treated with utmost confidentiality. They cannot be disclosed to third parties or used outside the intended scope for which permission is originally sought from the customer.
  • Lenders need to make certain mandatory disclosures informing consumers of their rights each time an adverse action is taken based on information in their credit reports.
  • Use of factors such as age, gender, race or exact geographic location in the credit scoring models is expressly forbidden to prevent any form of discrimination.
  • The interest assessments must be made exactly as advertised to customers when accounts are booked. The formulas used in calculation should be explained in the statements sent to customers.
  • Consumers reserve the right to instruct the credit bureaus to make their credit file inaccessible to lenders making unsolicited offers and thereby opt out of mass mailing campaigns, telemarketing campaigns and so on.

Contact with borrowers for debt collection can only be made between 8 a.m. and 9 p.m. Dunning by telephone or in person more than once week, contacting the borrowers at their workplace without prior permission and using inappropriate or strong language might be construed as harassment in the court of law with harsh penalties for the credit provider as well as the collection agency involved, if any. (Contrast this with the goons hired for collections in India and the abuse defaulters suffer.) In India there are credit providers, credit facilities, credit bureaus and credit data sharing processes that mirror the American model, but we cannot boast of a comparable regulatory rubric for governing them.


The stage is now set for a grand credit circus wherein many unsuspecting consumers are lured into debt through inducements and then flung into a precarious trapeze dance with creditors, without a safety net to break their fall. The policymakers would do well to realise that the trapeze act involves a two-way grip, and if the consumers fall into debt traps they will take the creditors down with them.


A substantial portion of the NPAs stems from wilful defaults by big institutional borrowers rather than individual borrowers. These wilful defaulters enjoy political patronage and cash in on the loopholes and lethargy in our legal system.


The Indian corporate culture has been driven mostly by debt rather than equity for raising capital during the socialistic era that spanned four decades. The overhang of NPAs stemming from institutions rooted in such a past is unavoidable and is the price to be paid for development in a business environment that lacks the vigour of a risk-taking stock-market culture.


Consumer credit bureaus can do little to address such issues and make a deep dent in NPAs. But they can identify and potential fraudsters and defaulters from good customers and adopt a differential risk-based pricing strategy for their products.

Thus, customers with a good track record of managing their obligations will be rewarded in the form of lower interest rates, courtesy the "invisible hand" theory on market forces. This has certainly been true in the US. But only time will tell to what extent such benefits will reach consumers in India.

back to Credit Score articles

Tips for Safe usage

Here are some important tips which ones MUST carefully read and also follow for their own safety.

You must always sign at the back of your credit card as soon as it arrives

Memorize or note down your 3 digit CVV number and blacken it on the card

Always ensure that your credit card is swiped in your presence. 5 Star Hotels or Clubs are no excuses.

Store your card particulars in a safe place, separate from the card so that you can access this in the event the card is stolen.

In the event of your card being stolen, inform the card company immediately and get the card blocked.

Subscribe to SMS Alerts, if they are offered and work at all [HDFC Bank's Alerts are useless] ICICI Bank's alert are really real time. ICICI Bank sends alerts to your mobile immediately after every transaction.

When your credit card expires, cut into atleast 3 pieces such that the magnetic piece is also cut at 3 different places.

The credit card companies [including SBI, HDFC, etc] in India are functioning really below expectations and if you decide to have one, you should be extremely careful as the regulator RBI and Finance Ministry are least bothered about citizens woes.

Credit Card Safety


Although the numbers are increasing, consumers are still not using their credit cards on the Internet nearly as much as e-tailers (electronic retailers) would like. That's why many cyber-merchants continue to offer a toll-free order number so that shoppers have the choice of calling their order in. Cyber-shopping may be convenient -- and some people do all of their shopping online -- but credit-card fraud is always a threat, both on the Internet and out in the real world. Hackers have found ways to steal credit-card numbers from Web sites.

To illustrate the importance of tight security, a network TV reporter, tipped off about loose security on an Internet Web-hosting site, was able to gain access to about 1,500 customer records, which included everything from credit-card numbers and payment records to comments about particular customers.

These are the kinds of stories that deflate consumer confidence. Some e-tailers blame consumer reluctance on the inability in cyberspace to make the kind of personal contact that a shopper gets when he looks into the eyes of a store merchant. Experts say that this kind of comfort level will be boosted when online payment methods and security measures are standardized -- much as they are in the retail and mail-order industries.

While Internet companies have taken responsibility for security breaches and resulting losses to credit-card users, there remains the growing problem of identity thieves who use stolen credit cards to make purchases on the Internet. And while unfair or fraudulent practices by credit-card companies are not commonplace, they do happen. The good news is that consumers are protected by law -- in case of credit-card fraud online or off, you are only liable.

And fortunately, the Federal Trade Commission (FTC) and the media are watching closely. In 1994, the FTC ordered TransUnion credit-reporting bureau to stop selling "sensitive" consumer data -- data on 160 million Americans -- to junk-mail producers. The FTC charged that TransUnion violated the Fair Credit Reporting Act by selling consumer information to target marketers who lack any of the allowable purposes listed under the act. TransUnion denies that it sold information that could affect customers' appealed the FTC's ruling, but lost.

If the mailing-list issue bothers you -- and it bothers most of us -- pay attention when you're completing that credit-card application. Some application forms now provide a box that you can check to allow or disallow the selling of your information to mailing lists. You can also protect yourself by taking your name off the credit bureaus' mailing lists.

The Direct Marketing Association (DMA) tracks consumers who prefer not to receive solicitations by mail or phone. Check their Consumer Assistance site for more information. There are a lot of simple steps you can take to protect yourself and your credit card -- starting with making sure you sign it as soon as it arrives in the mail.

These tips are important and universal:
  • Sign your card -- as soon as you receive it! (Obviously, this is only as effective as the clerk who's checking it.)
  • When you use your card at an ATM, enter your PIN in such a way that no one can easily memorize your keystrokes.
  • Don't leave your receipt behind at the ATM.
    Your PIN and account number from a discarded receipt could make you vulnerable to credit-card fraud. Also, don't throw out your credit-card statement, receipts or carbons without first shredding them!
  • Never give your credit-card number over the telephone unless you initiated the call.Even when you place the call to a legitimate merchant (such as a mail-order company), never give your card number out over a cordless phone. Radio scanners that eavesdrop on these conversations are available for a few hundred dollars at any electronics store, and your voice can be received by one from a far greater distance than the maximum useful range of your cordless phone. One common scam is when someone calls you "back" right after you place an order, claims to be from the merchant and tells you that there was a problem with your card number -- would you mind giving it to them again? The best thing to do is ask for a contact name and call the merchant back at the number you used originally.
  • Ignore any credit-card offer that requires you to spend money up-front or fails to disclose the identity of the card issuer.
  • Make certain you get your card back after you make a purchase (one habit to observe is to leave your wallet open in your hand until you have the card back). Also, make sure that you personally rip up any voided or cancelled sales slips.
  • Always keep a list of your credit cards, credit-card numbers and toll-free numbers in case your card is stolen or lost.
  • Check your monthly statement to make certain all charges are your own, and immediately notify the card issuer of any errors or unauthorized charges. (More on this later!)