Share this
What is Transaction Reversal Fraud?
by Admin
Transaction Reversal Fraud (TRF) is a method of obtaining cash from an ATM without the account used to initiate the transaction being debited. This is typically accomplished by the criminal inducing a fault at the ATM during the cash dispense operation such that the host application software logic will reverse the transaction (i.e. not debit the account), although the ATM will dispense the cash and the criminal will remove it from the ATM.
Criminals will typically use anonymous accounts for this fraud to avoid detection, often using prepaid cards or stolen or skimmed cards. This particular form of TRF has been reported in the United Kingdom, Ukraine, and Canada to date. The typical ATM models attacked are Through-The-Wall (TTW) ATMs.
The M.O. in the recent reports uses a technique that causes a fault at the ATM card reader during the cash dispense transaction. A card and PIN are correctly entered into the ATM, and a cash withdrawal is requested. While the transaction is being authorized at the host, the ATM will pre-position the bills behind the dispenser shutter, ready to dispense. The card is ejected, and rather than take the card as per a normal transaction, the criminal leaves the card in the slot.
The ATM transaction will timeout, and the card reader will attempt to capture the card. At this point, the criminal will hold onto the card preventing it from being captured. This results in the ATM reporting a card jam, and because no cash has been dispensed, the host software will reverse the transaction. Now the criminal will force open the dispenser shutter and remove the cash before the ATM has an opportunity to put the cash into the dispenser reject bin.
Get in touch with our experts >
FTSI has over 25 years of experience in financial institution security. We are available to discuss your strategy and help you overcome roadblocks.
If you want to better protect your financial institution from TRF attacks, contact solutions@ftsius.com today.
Share this
- 2024 September (1)
- 2024 July (5)
- 2024 May (1)
- 2024 March (2)
- 2024 February (1)
- 2023 December (1)
- 2023 October (3)
- 2023 September (1)
- 2023 August (3)
- 2023 July (2)
- 2023 June (2)
- 2023 May (2)
- 2023 April (1)
- 2023 March (2)
- 2023 January (2)
- 2022 December (4)
- 2022 November (5)
- 2022 October (1)
- 2022 September (5)
- 2022 August (2)
- 2022 July (1)
- 2022 April (2)
- 2022 March (1)
- 2022 January (1)
- 2021 October (3)
- 2021 September (2)
- 2021 June (1)
- 2021 April (1)
- 2020 December (1)
- 2020 October (1)
- 2020 May (2)
- 2020 March (2)
- 2020 February (1)
- 2020 January (1)
- 2019 October (1)
- 2019 September (1)
- 2019 May (1)
- 2019 March (2)
- 2019 January (3)
- 2018 July (1)
- 2018 June (1)
- 2018 April (2)
- 2018 January (1)
- 2017 December (1)
- 2017 November (1)
- 2017 September (1)
- 2017 August (1)
- 2017 June (1)
- 2017 May (1)
- 2017 April (1)
- 2017 March (1)
- 2017 February (2)
- 2016 December (1)
- 2016 November (1)
- 2016 July (1)
- 2016 February (1)
- 2015 December (1)
- 2015 September (2)
- 2015 June (1)
- 2015 May (2)
- 2015 April (1)