A second wave of attacks began midday Friday after much of the eastern United States was affected in the morning. Sites affected included Etsy, ...
Some card-issuing banks still aren’t technologically equipped to validate CVV2 codes in real time. Over the holidays Progressive Distribution found banks unable to process the codes in 10% to 15% of transactions across its customer base.
CVV2 codes-the unique 3-digit numbers aimed at providing additional security in online and other card-not-present transactions-are now routinely printed on the backs of credit cards. But some card-issuing banks still aren’t technologically equipped to process the codes, even when they’re printed on their own cards. John McGovern, president of integrated e-commerce and distribution management services provider Progressive Distribution Services Inc., estimates that over the holiday shopping season, CVV2 codes could not be automatically verified in real time by the card issuing bank in 10% to 15% of transactions processed through Progressive’s platform.
“It was a revelation to us over this holiday season,” says McGovern. “In some cases, when we transmitted it out over the network, we got a response back from the bank through the network that the codes were not yet supported.” In those circumstances, he notes, escalation measures already built into Progressive’s platform kicked in to cover the transaction.
Progressive recently made the verification of CVV2 codes, first introduced by credit card companies about three years ago, standard on its platform for all the retailers as well as other b2c businesses who are its customers. Over the past 12 months, McGovern estimates, verifying the codes has helped reduce bad debt from fraudulent online transactions by about 50%. The codes, which are never printed on retail receipts, are intended to establish that the person placing the order has the card in hand and hasn’t simply picked the card number off a store or restaurant ticket.
But the technology to validate the codes in real time is being implemented more slowly at some banks, such as smaller banks, McGovern says. He notes that other transaction processors may be having a different experience with banks’ ability to verify the codes in real time, depending on the nature of their customer base and whether the card-issuing banks involved skew toward larger and more technologically advanced establishments. However, “We do have a diverse customer base, so this percentage is probably pretty close,” he says.