The recent hacking incident involving Equifax has made many people fearful for their personal data. Although this attack was extremely tragic, it is not the first cyber attack of its kind in this field. Naturally, nonprofit organizations will not be safe from such breaches. For this reason, I asked an expert for advice on what nonprofit organizations can do to protect themselves and their donors from such security breaches.
In this context, Ged Mackey, the Director of Technology and Security at the nonprofit organization MobileCause, mentioned a problem called “credit card testing.” A report released by Symantec earlier this year revealed that nearly half of all American companies have experienced more than one cyber attack, many of which focused on stealing credit card information. Following this breach, these digital criminals test the stolen credit card numbers by making small donations online to verify that the card is still active.
This type of crime is referred to as “credit card testing,” which saw a significant increase of 200% during 2017. This tactic can be manual or automated and is used by scammers to test stolen credit card numbers and verify their validity.
In fact, this type of hacking targets nonprofit organizations, as a “denial of service attack” can shut down the network or the payment processor itself. This means that the bank you work with will stop accepting donations or payments until the issue is resolved. Additionally, these criminals ensure the validity of each card online, which becomes highly valuable in the black market and is quickly used to procure other high-value goods and services.
Moreover, it seems that this ability to verify small amounts in the tens of thousands that exist in various types of cards held by many people across many countries works more reliably with nonprofit organizations compared to large companies, because these targets often lack sufficient monitoring controls for fraud.
As a result, nonprofit organizations are particularly vulnerable to risk since they often rely on simple online technologies to facilitate the donation process for donors, just like purchasing any type of digital goods, which do not require a shipping address to complete the transaction.
Unfortunately, this type of fraud damages the reputation of many nonprofit organizations. It is worth noting that hackers can identify security vulnerabilities, so nonprofits must take certain measures:
First, organizations should identify their weaknesses. Storing credit card numbers manually in a printed copy or on an unencrypted file on a computer makes nonprofits susceptible to Internet criminals, which can lead to significant financial losses.
Second, nonprofit organizations should only work with credit cards whose payment processors adhere to the highest security standards and regulations.
Third, the global visa register of service providers is another way for nonprofits to verify the payment processors they choose.
– Increase employee and donor education on the importance of cybersecurity, and identify each person's role in it, by monitoring their online activities. The best way to make payments online is to ensure a payment intermediary that does not store credit card data.
– Qualified vendors must encrypt card data as soon as it is entered on the designated payment page in a manner that cannot be read at all.
– An emergency plan should be implemented to ensure that the donor is alerted in case the page is breached and data is stolen. This plan should include clear instructions for the donor to apply in order to mitigate the damage they have suffered.
From this standpoint, relying on a limited number of payment sites is one of the best precautions nonprofits should follow to reduce cyber attacks, as those sites request specific data from the donor. Additionally, nonprofits should activate the reCAPTCHA system, which works to confirm the user’s identity, and use speed checks that continuously examine the patterns that repeat during the payment process within a certain timeframe.
While the above-mentioned measures help secure protection against cyber attacks, there are some paid applications that could provide even better protection against this type of attack. Nonprofit credit cards are the most susceptible to attacks, so these organizations need to act quickly to take the necessary measures.
—————————————————–
Source: Clairification
Author: Site Edits
Comments (0)
No comments yet. Be the first to comment!