Lessons from a breach

by Cherian Abraham 6 min read January 14, 2014

In the days following the Target breach, both clarity and objectivity are in short supply. Everything that didn’t already exist became suddenly the cure-all – EMV being one. Retailers bristle, albeit in private – due to the asymmetry in blame they have come to share compared to banks – despite having equal ownership of the mess they have come to call payments. Issuers and Schemes scramble to find an empty deck chair on the Titanic, just to get a better view of the first of the lifeboats capsizing.

Analogies aside, we may never fully eliminate breaches. Given an infinite amount of computing power and equal parts human gullibility – whether its via brute forcing encryption systems or through social engineering – a breach is only a matter of time. But we can shorten the half-life of what is stolen. And ensure that we are alerted when breaches occur – as fraudsters take care to leave little trace behind. Yet today our antiquated payments system offer up far too many attack vectors to a fraudster, that the sophistication in attempts of the likes of what we saw at Target, is the exception and not the norm. But are the retailers absolved of any responsibility? Hardly.

Questions from a breach:

According to Target, malware was found on Target’s PoS – presumably pushed by unauthorized outsiders or via compromised insiders. If so, how is it that unauthorized code managed to find its way to all or most of its PoS terminals? Could this have been uncovered by performing a binary or checksum comparison first, to ensure that files or packages are not tampered with, before they are deployed to the Point-of-Sale? Such a step could have certainly limited the attack vectors to a small group of people with administrative access – who would have the need to handle keys and checksums.

Further, depending on the level of privilege accorded to every binary that gets deployed to the point of sale – Target could have prevented an unauthorized or remotely installed program from performing sensitive functions such as reading consumer data – either in transit or in RAM. That said – I am not sure if PoS manufacturers provide for such layered approach towards granting access and execution privileges to code that is deployed to their systems. If not, it should.

Where DOES EMV come in?

EMV helps to verify the card – indisputably. Beyond that, it offers no protection to either the consumer or the merchant. The risk of EMV, and it’s infallibility in the eyes of its true believers, is that it can lull the general public in to a sense of false security – much like what we have now under Reg E and Reg Z. With EMV, PAN and PIN continues to be passed in the clear, unencrypted. Retailers could deploy EMV terminals and still be riddled like cheese by fraudsters who can siphon off PANs in transit. Fraudsters who may find it nearly impossible to create counterfeit cards, instead will migrate online where inadequate fraud mitigation tools prevail – and those inadequacies will force both banks and retailers to be heavy handed when it comes to determining online fraud. Friction or Fraud should not be the only two choices.

Solving Card Not Present Fraud:

There are no silver bullets to solve Card Not Present fraud. Even with EMV Chip/Pin, there is an opportunity to put a different 16 digit PAN on the front of the card versus the one that is on the magstripe/chip. (I am told that Amex does this for its Chip/pin cards.) The advantage is that a fraudster using a fraudulently obtained PAN from the chip for an e-commerce purchase will standout to an card issuer compared to the legit customer using a different PAN on the front of the card for all her e-commerce purchases. This maybe one low tech way to address CNP fraud alongside of an EMV rollout.

But if asking a consumer to enter his Zipcode or show his ID was enough for retail purchases, there exists equivalent friction-bound processes online. Authentication services like 3-D Secure are fraught with friction, and unfairly penalize the customer and indirectly – the retailer and issuer, for its blind attribution of trust in a user provided password or a token or a smart card reader. Where it may (in some cases) undeniably verifies consumer presence, it also overwhelms – and a customer who is frustrated with a multi-step verification will simply shop somewhere else or use Paypal instead. Ever had to input your Credit Card Verification code (CVV2 or CVC2) on an Amazon purchase? Me neither.

Fraud in connected commerce:

As connected devices outnumber us, there needs to be an approach that expands the notion of identity to look beyond the consumer and start including the device. At the core, that is what solutions like 41st Parameter – an Experian company, focuses on – which enables device attributes to collectively construct a more sophisticated indicator of fraud in an e-commerce transaction – using 100 or so anonymous device attributes. Further it allows for more nuanced policies for retailers and issuers, to mitigate fraud by not only looking at the consumer or device information in isolation – but in combination with transactional attributes. As a result, retailers and issuers can employ a frictionless, smarter, and more adaptive fraud mitigation strategy that relies less on what could be easily spoofed by a fraudster and more on what can be derived or implied. If you want to know more why this is a more sensible approach to fighting fraud, you should go here to read more about 41st Parameter.

Remnants from a breach:

Even though the material impact to Target is still being quantified, little doubt remains as to the harm done to its reputation. Target RED card remains largely unaffected, yet it is but a fleeting comfort. Though some, thus had been quick to call decoupled debit a more secure product, those claims choose to ignore the lack of any real consumer protection that is offered alongside of these products. Though Reg E and Reg Z have been largely instrumental in building consumer trust in credit and debit cards, they have also encouraged general public to care less about fraud and credit card security. And this affects more than any other – MCX, whose charter calls for reduction of payment acceptance costs first, and to whom – decoupled debit offered a tantalizing low cost alternative to credit. But when it launches this year, and plans to ask each customer to waive protections offered by Reg E and Reg Z and opt for ACH instead – those consumers will find that choice harder to stomach. Without offering consumers something equivalent, MCX Retailers will find it exceedingly difficult to convince customers to switch. Consumer loyalty to retailer brands was once given as the reason for creating a retailer friendly payment backbone, but with Target’s reputation in tatters – that is hardly something one can bank on these days – pun intended.

Where does this leave us?

To be completed…

This blog post was originally featured at:http://www.droplabs.co/?p=964

Related Posts

Fuel Type Choices Continue to Reshape Vehicle Registration Trends

Electric vehicle (EV) registration growth has become a common topic of discussion throughout the automotive industry for the last few years, but the bigger story may lie in what consumers are choosing when they return to market for their next vehicle. According to Experian’s Automotive Market Trends Report: Q1 2026, the bulk of EV owners (72.6%) purchased another EV, while 17.7% replaced their EV with a gas-powered vehicle and 5.6% switched to a hybrid this quarter. A similar trend was seen in hybrid owners, as 54.9% remained loyal to the fuel type through the quarter, while 32.7% replaced their hybrid with a gas-powered vehicle and 7.5% switched to an EV. Notably, 78.2% of consumers with gas-powered vehicles stayed with the same fuel type, with 5.6% swapping their gas vehicle for a hybrid and only 4.5% transitioning to an EV through Q1 2026. These purchase styles suggest that while most consumers are not making a direct leap from gasoline to fully electric vehicles, some are beginning their electrified journey through hybrid ownership. At the same time, the high rate of fuel-type loyalty across all powertrain categories highlights the importance of the ownership experience. Consumers who are satisfied with their current vehicle can often be inclined to remain with the same segment rather than exploring alternative fuel types. New vehicle registration trends reflect changing consumer preferences Looking at the new vehicle registration data from a broader level, gas-powered vehicles experienced a slight uptick, coming in at 69.5% through Q1 2026, from 67.3% last year. Meanwhile, hybrids continue to grow, going from 12.1% to 13.5% year-over-year while EVs steadily decline from 7.8% last year to 5.6% this quarter. As consumers weigh their next vehicle purchase, many seem to be sticking with the standard gas-powered choice, and others are finding a happy medium in hybrid vehicles. And while EVs receive much of the industry’s attention, buyers are exploring alternatives that allow them to adopt the electrified vehicles incrementally rather than all at once. To learn more about vehicle market trends, view the full Automotive Market Trends Report: Q1 2026 presentation on demand.

Published: June 12, 2026 by John Howard
Rewriting the Road Ahead with Longer Loan Terms and Increased Refinancing Options

The automotive market is entering a new phase defined not just by what consumers are buying, but by how they’re choosing to finance it. According to Experian Automotive’s State of the Automotive Finance Market Report: Q1 2026, nearly one-third (35.55%) of all new vehicle loans now stretch more than six years, up from 30.83% in Q1 2025. Similarly on the used side, 31.54% of loans extended more than six years, an increase from 28.60% last year. The shift highlights why affordability is reshaping how consumers are financing their vehicles, particularly in larger and higher-priced vehicles. Refinancing gains traction as interest rates stabilize In addition to longer-term loans, consumers are becoming increasingly deliberate with their financing decisions and managing monthly payments as refinancing activity has gained momentum. For instance, consumers who refinanced this quarter lowered their interest rate by 2.2% and saved an average of $81 on their monthly payment. Credit unions, in particular, continued to play a major role in helping consumers secure more affordable payment options. In Q1 2025, credit unions accounted for the lion’s share of automotive refinancing at 63.43%, from 62.31% a year ago. By comparison, banks went from 23.51% to 22.59% year-over-year. Furthermore, those who refinanced with a credit union saved an average of $101 this quarter, whereas those who refinanced with banks saved $60. Expanding credit access through flexible financing Another notable trend this quarter was the incessant growth in subprime financing as credit accessibility across the market continues to increase. In the first quarter of this year, subprime borrowers made up 15.75% of total vehicle financing, from 14.40% last year. For new vehicles in particular, the subprime market went from 5.61% to 6.88% year-over-year, while subprime in used vehicle financing grew to 20.60% this quarter, from 19.36% a year ago. Increased activity in the subprime segment highlights continued confidence in the automotive market and underscores the importance of expanded financing options. As consumers seek greater flexibility with financing decisions that fit their lifestyle, lenders and dealers have the opportunity to approach them with more personalized solutions. These trends are helping keep both new and used vehicle markets moving forward, while creating new opportunities for consumers to manage payments and purchase confidently. To learn more about automotive finance trends, view the full State of the Automotive Finance Market Report: Q1 2026 presentation on demand.

Published: June 2, 2026 by Melinda Zabritski
Staying Competitive After Trigger Leads Evolve: A Roadmap For Lenders

Trigger leads have long been the preferred solution for identifying high-intent mortgage borrowers. But with the implementation of the Homebuyers Privacy Protection Act (HPPA), which introduces new limitations and consumer protections around trigger leads, that playbook will need to shift. Now, lenders are quickly facing a pivotal shift in how they discover, engage, and convert prospective borrowers into customers. The industry now stands at a crossroads. Lenders who adapt early—leaning into predictive tools, consent-based engagement, and smarter prescreening—will redefine borrower acquisition in a more privacy-centric era.  HPPA: A structural change to mortgage marketing  The HPPA amends the Fair Credit Reporting Act by significantly restricting the use of mortgage inquiries for prescreen purposes. As of March 5, 2026, credit bureaus may only provide or utilize mortgage inquiries to:  End users with explicit borrower consent  The originator of the consumer’s current mortgage  The servicer of the consumer’s current mortgage  An insured depository institution or credit union where the consumer has an existing account  While these exemptions may provide continuity for banks and credit unions, many mortgage brokers and nonbank lenders will need to overhaul their prescreen practices—or risk being cut off entirely from a previously high-performing acquisition channel.  Why this isn’t just a compliance shift—It’s a strategic recalibration  Mortgage triggers in prescreen allow lenders to react instantly to consumer intent. Lenders rely on a prompt and convincing narrative to entice applicants to switch lenders. Mortgage inquiry triggers are effective and were, therefore, a prospecting strategy for many lenders. Recent legislative changes significantly restrict the availability of these inquiry triggers, and impacted lenders are focusing on a more intentional prospecting strategy to compete.   Without these mortgage triggers in prescreen, lenders need to ask:  Who are we trying to reach?  What early signals can we act on?  How do we earn permission and attention before a mortgage inquiry ever happens?  Transforming the funnel: From reaction to anticipation  The shift in mortgage inquiry-based prescreen isn’t the end of high-intent lead targeting. It’s the beginning of a more strategic and intentional approach—one that leverages earlier indicators of mortgage readiness and focuses on building relationships, not just closing transactions.  Here’s where the momentum is evolving, creating a new and smarter funnel:  Prescreen marketing: Using credit and behavioral attributes to help identify consumers who meet specific lending criteria before they signal active intent.  Predictive modeling: Leveraging propensity scores or custom models to prioritize outreach based on conversion likelihood.  Consent-based engagement: Implementing compliant mechanisms to capture and manage borrower opt-ins at scale.  The power of predictive modeling  According to recent industry interviews, propensity modeling is emerging as one of the most effective replacements for trigger-based prescreen. These models analyze hundreds of credit attributes—such as utilization, account mix, account age, and depth—to help identify consumers statistically more likely to seek a mortgage.  For lenders just beginning to use predictive modeling, off-the-shelf models can be a quick way to identify potential borrowers. For example, when layering propensity scores on top of credit eligibility, which can improve borrower targeting, many lenders see an increase in open mortgage loan rates.  Meanwhile, custom-built models, which analyze a lender’s own campaign performance over time, offer the highest level of precise targeting. These models isolate the attributes most predictive of conversions within a specific product mix—optimizing not just volume, but fit.  Speed without traditional triggers? It’s possible  One of the biggest concerns among lenders is maintaining the speed historically enabled by trigger leads. But that concern may be overblown.  Self-service prescreen platforms now allow marketers to generate qualified lead lists in as little as 24 hours, enabling rapid response during rate drops, competitive shifts, or seasonal demand spikes.   For those new to prescreening, batch campaigns still offer value, especially with analyst support.   Don’t overlook retention  In an era of intense acquisition competition, retention becomes a key differentiator.  Lenders who monitor property status, cash flow, and consumer credit behavior can proactively identify when an existing borrower is likely to list, refinance, or exit. Armed with that intelligence, lenders can re-engage with the borrower at the right moment—sometimes before a competitor is considered or contacted.  This level of behavioral intelligence may soon separate proactive lenders from reactive ones.  Actions instead of reactions  The evolution of trigger-based prescreen doesn’t just require new tools; it demands new thinking. Lenders should begin by auditing their current pipelines and determining:  What percentage of our acquisition is dependent on triggers?  What share of our book falls under the HPPA exemptions?  How will we scale compliant opt-in collection?  Are our current prescreen or modeling capabilities future-ready?  Those who answer these questions today—and act on them—won’t just be in compliance with the new laws, they’ll lead in a transformed market. Lenders should also be asking:   Do we have the infrastructure to collect and act on borrower consent?  Are our acquisition teams equipped to run prescreen campaigns — both batch and self-service?  What predictive models are we using (or could we use) to prioritize leads?  Are we proactively monitoring our portfolio to catch retention risks early?  How are we preparing our sales teams for longer, more consultative buying journeys?  Conclusion  The HPPA signals a shift away from relying on passive, inquiry-based prescreen acquisition and the beginning of smarter, more strategic engagement with potential borrowers. Lenders who embrace this transition early will find themselves not just compliant, but competitive—with deeper borrower insights, better conversion rates, and stronger long-term customer relationships.  The market is moving. The only question is: will you lead the change or chase it?  Citation  Experian. (2025, November). Interview: How the Homebuyers Privacy Protection Act is reshaping mortgage marketing—and what lenders should do now [transcript]. Experian Mortgage Insights. Insights based on lender feedback, campaign performance data, and analysis of prescreen marketing strategies and predictive modeling outcomes were gathered from Experian client engagements and internal mortgage analytics between May and October 2025. Homebuyers Privacy Protection Act timeline and legal context referenced from legislation signed September 5, 2025, with implementation beginning March 5, 2026.   

Published: April 22, 2026 by Ivan Ahmed