<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Application of information technology to combat cyber fraud1</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Anna S. Zueva</string-name>
          <email>zueva@audit.msu.ru</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Daria A. Musatova</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Valentina V. Britvina</string-name>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Alexey Yu. Sorokin</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Gulmira E. Nurgazina</string-name>
          <xref ref-type="aff" rid="aff3">3</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Academy of Civil Protection of the Ministry of Emergency Situations of Russia</institution>
          ,
          <addr-line>1, Sokolovskaya, Khimki, 141435, Russian Federation</addr-line>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Lomonosov Moscow State University</institution>
          ,
          <addr-line>1, Leninskie Gory, Moscow, 119991</addr-line>
          ,
          <country country="RU">Russia</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>Moscow Polytechnic University</institution>
          ,
          <addr-line>38, st. Bolshaya Semyonovskaya, Moscow, 107023, Russian Federation</addr-line>
        </aff>
        <aff id="aff3">
          <label>3</label>
          <institution>Russian State Academy of Intellectual Property</institution>
          ,
          <addr-line>55 a, Miklukho-Maklaya street, Moscow, 117279, Russian Federation</addr-line>
        </aff>
      </contrib-group>
      <abstract>
        <p>This paper is devoted to the consideration of various types of cyber attacks. The purpose of this paper is to analyze NFC fraud, phishing web pages, PayPal fraud, fake call centers. To explore this topic, we studied the experience of Canada in the field of cyber attacks. The article also discusses the most important aspects of banking and government regulation in this area and methods of combating cyber attacks.</p>
      </abstract>
      <kwd-group>
        <kwd>carding</kwd>
        <kwd>cyber scamming</kwd>
        <kwd>cyber-attacks</kwd>
        <kwd>fraud</kwd>
        <kwd>payment systems</kwd>
        <kwd>phishing</kwd>
        <kwd>NFC fraud</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>In a modern society there is a powerful trend of consumption. People are
economically active as never before and consume enormous amounts of goods and services.
More than that, people tend to prefer plastic cards to cash. A technological progress
constantly brings up new improvements to payment systems, and banks advertise
them as a more secure and advanced alternatives to carrying cash around. To find out
if it is right or wrong, we are going to analyze the world of plastic cards, digital
payment systems and find all possible dangers that can await bank customers. The
technological progress not only provides newer options of how people can make
transactions but it also gives thieves an access to a new area where they can commit crimes
and still keep their identities hidden. As Javelin Strategy &amp; Research says, about $6.4
billion were stolen from peoples’ credit cards by scammers in 2018 in USA, and the
number tends to grow. More and more people each year become victims of hackers,
scammers that can collect personal information, control others’ bank accounts and
perform illegal activities.
1 Copyright c 2021 for this paper by its authors. Use permitted under Creative Commons License
Attribution 4.0 International (CC BY 4.0).</p>
      <p>The technological progress not only provides newer options of how people can
make transactions but it also gives thieves an access to a new area where they can
commit crimes and still keep their identities hidden. As Javelin Strategy &amp; Research
says, about $6.4 billion were stolen from peoples’ credit cards by scammers in 2018
in USA, and the number tends to grow. More and more people each year become
victims of hackers, scammers that can collect personal information, control others’ bank
accounts and perform illegal activities.
2</p>
    </sec>
    <sec id="sec-2">
      <title>Materials and methods</title>
      <p>In the process of writing this article, the following methods were used: methods of
analyzing the literature, analyzing regulatory documents, comparing the experience of
different states in the observable area, specific legal and comparative legal methods.
3</p>
    </sec>
    <sec id="sec-3">
      <title>Results</title>
      <p>People may not know but there is a constant danger of their bankcards to be attacked
by the criminals. There are many types of scamming, we are going to touch the most
common ones in order to find a way of protecting your bank accounts.
1. NFC Fraud</p>
      <p>
        Most of modern cards have a NFC chip, which allows to perform transactions
without entering your card in the payment terminal. So called “Paywave” technology
is accepted everywhere and people tend to use it. Modern smartphones can mimic
bankcards by using the NFC as well. What NFC does, is that it allows to hold a
bankcard near payment terminal and make a purchase without entering PIN or swiping a
card if the price of the purchase is under a certain limit that differs in regions. [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]
      </p>
      <p>
        Criminals use that technology to perform low-cost transactions with a payment
terminal. They can simply place the terminal close to your wallet and perform a
“purchase” without you even knowing it. This type of fraud is best performed in crowded
places like subway stations or malls. [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]
      </p>
      <p>
        To fight this kind of a scam, people can protect their money by storing all the
bankcards that feature NFC chips in special wallets that block any type of signal. If
you wrap your mobile phone or a credit card in tinfoil, you will see that no signal is
being received, nor any signal is being delivered. These wallets work the same way
but instead of wrapping your cards in pieces of aluminum, you can simply extract
cards from the wallet when they are needed. [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]
2. Phishing webpages
      </p>
      <p>
        Phishing websites are a very old trick that has been used by credit card scammers
for ages. These websites ask you to enter the whole information about your bankcard
including a card number, an expiration date, a CVV code and a PIN. [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ] First and
foremost, no other individual should know your PIN and even no bank employee can
ask you to name it. If anyone asks your PIN code, you must be sure that someone tries
to scam you. As Internet Crime Complaint Center (IC3) states, $48,241,748 was
reportedly lost per victim due to phishing attacks in 2018 (2018 Internet Crime Report).
      </p>
      <p>On the other hand, online stores will always ask your CVV code in order to
perform a payment. Phishing sites are usually presented as online stores, the main goal is
to trick you. Creators of such sites make a fake version of famous online stores, such
as Amazon or Ebay, and make them look identical to the real ones. In order to track
whether you are being redirected to a phishing site, you should check the URL of this
particular website. Buyers must use authentic websites, which can be found in
Google, Yahoo or Bing. These searching websites have a strict policy that restricts
any cyber frauds and developers always update their websites in order to protect users
from entering phishing webpages. Modern browsers have built-in scanning programs
that will alert you if something suspicious is happening, they will not allow you to
enter a scamming website.</p>
      <p>More than that, users should never enter links that could be sent to their e-mail
addresses by suspicious accounts that they have never seen before, nor they should
never click on advertisement pictures in order not to be scammed.</p>
      <p>These easy tips will protect users from losing their money, thankfully, program
developers always enhance and update their products in order to protect people that are
not experienced enough or not even aware of such type of a scam.</p>
      <p>3. PayPal scam</p>
      <p>
        Many internet users, buyers and sellers, use such services like PayPal, Shopify or
TranferWise. These technologies, particularly PayPal as the first ever and the most
popular, allow you to transfer money, make payments via a website that has your
bankcard attached to it. PayPal is a payment system that allows you to make safe
transactions in a short time. It became popular at the time when worldwide transaction
would take days or even weeks to send money from one bank account to another with
enormous fees and losses on currency conversion. [
        <xref ref-type="bibr" rid="ref10 ref11 ref9">9-11</xref>
        ]
      </p>
      <p>
        More than that, PayPal allows you to make full money return if you stumble upon
a scammer while buying a good from an online auction. Ebay was growing rapidly
and as it’s popularity rose, PayPal became the only possible way of guaranteeing a
safe purchase. If a particular good does not ship in time or if it is broken, Ebay will
cancel the payment and return it back to you. [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ]
      </p>
      <p>
        Because of its popularity, PayPal scams started to be a common problem among
people [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. Any criminal could access your PayPal account if he previously got
information about your e-mail address. Criminals can use your e-mail to change
PayPal’s password and block the access to your funds. Later, they would easily perform
online purchases by using your identity and sell brand new goods to extract cash.
      </p>
      <p>
        PayPal, being aware of this problem, started using two-factor authentication, which
requires you to enter a newly generated code that was sent to your second e-mail
address or your mobile phone. This safety feature was so good that most of other
ITcompanies have adopted it in order to secure their customers’ private information [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ].
      </p>
      <p>In order not to become a victim of such illegal actions, people should never send
their logins, passwords or e-mails that can give criminals any possibility to hack
accounts and use others’ savings. The only information that users can give publicity to
is their unique nickname, which is needed to send money when a transaction is being
made. This nickname corresponds to an account that has your delivery address and a
bank account that will receive or send funds.</p>
      <p>4. Fake call centers</p>
      <p>In 2019 CBC Television published a very deep investigation on how Canadian
bank customers can face a massive scam with low-interest credit cards. This story has
started after CBC News journalists received a database that featured all the personal
information of more than 3,000 Canadians including full names, birth dates, home
addresses, credit card numbers, PINs and CVVs. As an investigation went on,
journalist got the main idea of this fraud – scammers steal identities, not a credit card
number. If scammers know enough information about you, they are able to make hundreds
of new credit cards and get enormous revenues by using your identity.</p>
      <p>Scammers, in order to collect data, make phone calls and present themselves as
bank employee. These fake employees present you an option to lower credit card’s
interest rate by making one payment that can vary from $500 up to $5,000. As the
phone call continues, scammers ask a customer to verify his personal data. It is known
as the low-interest or rate reduction scam.</p>
      <p>The victims of the fraud are often people who are full of debts. Such acting of a
fake bank employee can easily attract them because they wish to find any possible
way of minimizing their debts.</p>
      <p>Speaking about scammers, there are illegal call centers in Pakistan that simply go
through Yellow Pages and make calls to everyone. The reason why Canada attracts
these scammers is countries’ legislation and banks’ safety policy.</p>
      <p>Even if people reject to pay for this fee or do not give any personal information, it
is already enough for criminals to collect the data. Scammers can use your mobile
phone number and mimic it with another SIM card. Then they download bank’s
application or use official website to login under a stolen identity. Scammers can easily
get the missing information about an individual by calling bank’s office or using an
official chat.</p>
      <p>If a criminal did not succeed in withdrawing funds from the initial credit card, he is
most likely to sell a list of people with all their personal information via Darknet.
Darknet is a special part of internet that could not be accessed through well-known
browsers like Safari, Internet Explorer or Google Chrome. To enter Darknet, you
should install a special browser called Tor in order to look through illegal auctions
that sell things like drugs, handguns, pornography and stolen credit card numbers. A
special thing about Darknet is that a user cannot be tracked because of a special
security system that hides user’s IP-address and his location. All transaction in these
auctions are made with crypto currency that cannot be tracked as well; buyers and sellers
of illegal content and goods keep their identities completely anonymous.</p>
      <p>The main problem why Canadians are in danger and why Canada is one of the
most frequent requests in Darknet auctions is because Canadian government does not
allow a credit freeze. What credit freeze is, it is an ability to block an access to the
credit report. By blocking an access to the credit report, no information can be passed
over and so no credit will be issued. This procedure is the most effective way to stop
identity thefts. 50 of 51 states in the United States, except a state of Michigan, have a
credit freeze law. Sad to say but Canada provides no option for people to make a
credit freeze, thus bank accounts and identities of Canadians are still in a great
danger. As Canadian Anti-Fraud Centre states, about $20,000,000 were lost to identity
fraud in 2018.</p>
    </sec>
    <sec id="sec-4">
      <title>Discussion</title>
      <p>
        In order to fight cyber scamming, banks and government should cooperate and create
a two-sided strategy how to minimize credit card and identity frauds. In 2018 IC3
observed and estimated about $2.7 billion losses because of cybercrime in USA only.
If we collect the worldwide value of money stolen via different scamming methods,
the numbers will be shocking [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ].
      </p>
      <p>Internet should be strictly controlled by the Secret Services because it is a area
where scammers are allowed to openly buy and sell illegal goods without being afraid
of being caught. Many countries still do not have laws that will punish hacking and
scamming which allows criminals to switch between banks and customers they hunt.
The best example of that will be Canadian imperfect law system that allows
scammers from Pakistan to rob and trick people.</p>
      <p>Huge IT-corporations like Google and Apple are very strict when it comes to their
customers’ privacy. These corporations often help American government in solving
security problems and provide advanced technologies that were developed to protect
American citizens’ privacy. More than that, Apple or Google have enough influence
to state about flawed laws and bring ideas of fixing them in order to eliminate a new
fraud scheme for cybercriminals.</p>
      <p>FBI has created its own cyber security departments, which work with online store
operations, ID frauds and data breaches.</p>
      <p>Such banks like Bank of America, Chase or Citi have enough influence and
expertise to give advice about law improvements. In 2018 Center for Strategic and
International Studies (CSIS) concluded that an economic damage to the global economy due
to cybercrime was close to $600 billion. In order to have a stable economic market,
banks and government should fight cyber scamming together.</p>
      <p>
        In 2015 banks presented a new chip technology called EMV. It was designed to
make bankcard more secure and to fight cloning. 4 years later, an amount of
counterfeit operations fell drastically from $3.6 billion in 2015 to $1.7 billion in 2018.[
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]
      </p>
      <p>On the other hand, an example of Canadian epidemic of identity fraud shows that
banks have to adjust and develop their security services in order to stop cybercrime.
Negligence could not be allowed to continue and banks should value their customers’
privacy over everything.
5</p>
    </sec>
    <sec id="sec-5">
      <title>Conclusion</title>
      <p>As we have previously discussed, there is a relevant problem of cybercrime in our
society. The technological progress not only brings user-friendly applications and
gadgets but it also gives birth to new and devious ways of stealing money and
valuable information.</p>
      <p>In order to protect their personal information and savings, people need to be more
careful with their mobile devices, e-mails they receive and different calls they receive.</p>
      <p>To let people know about the global scope of cybercrime, banks and government
should engage mass media like radio stations, TV channels, newspapers, web
bloggers with a mission to tell people about their insecurity.</p>
      <p>Banks should develop and introduce more secure products to create a safer
environment for customers and bankcard users. We all should remember that when money
gets out of legal circulation, we will all suffer from it. Prices of goods and services
will increase rapidly, while our disposable incomes will decrease. More than that,
there will be a constant chance of losing all your savings because of personal
information leakage or your own carelessness.</p>
      <p>Our protection should stop being reactive, we cannot act and fix laws or security
systems only after a crime is being committed.</p>
      <p>Never the less, basic examples that have reviewed will definitely protect bank
accounts and minimize the level of cyber frauds. Scamming is a serious problem that
should never be dismissed and every individual should be familiar with it.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1. Fundera 2019 research, https://www.fundera.com/resources/cash-vs
          <article-title>-credit-cardspending-statistics.</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2. Forbes 2018 research, https://www.forbes.com/sites/tomgroenfeldt/2019/03/18/creditcard-fraud
          <article-title>-is-down-but-account-fraud-which-directly-hurts-consumers-remainshigh/#5442522020bf.</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <surname>Coskun</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ozdenizci</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ok</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          :
          <article-title>A survey on Near Field Communication (NFC) Technology</article-title>
          . Wireless Personal Communications,
          <volume>71</volume>
          (
          <issue>3</issue>
          ),
          <fpage>2259</fpage>
          -
          <lpage>2294</lpage>
          (
          <year>2013</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Turban</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>King</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lee</surname>
            ,
            <given-names>JK.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Liang</surname>
          </string-name>
          , TP.,
          <string-name>
            <surname>Turban</surname>
          </string-name>
          , DC.:
          <article-title>Electronic Commerce Payment Systems</article-title>
          .
          <source>Electronic Commerce. Springer Texts in Business and Economics</source>
          . Springer, Cham.,
          <fpage>519</fpage>
          -
          <lpage>557</lpage>
          (
          <year>2015</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5. 2018 Internet Crime, https://www.thesslstore.com/blog/20-phishing-statistics
          <article-title>-to-keepyou-from-getting-hooked-in-2019.</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <year>2018</year>
          IC3, https://www.digitalshadows.com/blog-and-research/fbi-ic3
          <string-name>
            <surname>-</surname>
          </string-name>
          cybercrime
          <string-name>
            <surname>-surgesin-</surname>
          </string-name>
          2018
          <string-name>
            <surname>-</surname>
          </string-name>
          causing-2
          <article-title>-7-billion-in-losses/.</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <given-names>EMV</given-names>
            <surname>Chips</surname>
          </string-name>
          , https://www.creditcards.com/emv-chip.
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          <article-title>8. Identity and credit card frauds</article-title>
          , https://www.creditcards.
          <article-title>com/credit-card-news/creditcard-security-id-</article-title>
          <string-name>
            <surname>theft-</surname>
          </string-name>
          fraud-statistics-
          <volume>1276</volume>
          .php.
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>9. Visa, https://en.wikipedia.org/wiki/Visa_Inc.</mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>10. American Express, https://en.wikipedia.org/wiki/American_Express.</mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>11. MasterCard, https://en.wikipedia.org/wiki/Mastercard.</mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <surname>Mobile</surname>
          </string-name>
          <article-title>Phishing Attacks and Mitigation Techniques</article-title>
          .
          <source>Journal of Information Security</source>
          , http://www.scirp.org/journal/jis/.
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>