Debated in Parliament on 5 Jul 2023.
Mr Saktiandi Supaat asked the Prime Minister (a) in each of the last five years, what is the total value of unauthorised credit card charges that have been reported; and (c) what regulatory measures are being considered or implemented to protect Singaporeans against Bank Identification Number attacks.
A Bank Identification Number (BIN) attack is a type of card fraud, using software to generate possible credit and debit card number combinations, expiration dates and card verification values. Low value transactions are systematically attempted in order to test for valid card details and higher value transactions are subsequently made using those valid card information.
The statistics requested by the Member are not readily available. Unauthorised credit card transactions, in particular, arising from BIN attacks, are not specifically tracked. Banks, however, track credit card dispute cases, which may comprise disputes over goods purchased or services rendered, card fraud, lost or stolen cards or scams. Of these, scams continue to be the main driver of losses suffered by consumers.
In BIN attacks, the fraudster typically targets merchants that do not require one-time password (OTP) authentication, as the fraudster would not ordinarily have access to the OTP. In such a case, a card user will not be liable for an unauthorised transaction. Rather, the merchant involved will be liable for the loss, as long as the card user reports the case on a timely basis.
Members of the public are strongly encouraged to monitor their card transactions regularly, and immediately notify their card issuers if they notice any fraudulent or suspicious transactions and also report such transactions to the Police.