Friday, December 18, 2009, 7:53AM ET - U.S. Markets open in 1 hour and 37 minutes.

Laura Rowley Money & Happiness

Laura Rowley, Money & Happiness

Protecting Yourself from Debit-Card Fraud

by Laura Rowley

Very Good (117 Ratings)
3.957268/5
Posted on Wednesday, November 11, 2009, 12:00AM

Last week, my Yahoo! Finance column looked at the growth in high-interest checking accounts that require consumers to jump through certain hoops, including use of a debit card 10 or more times a month. But frequent debit transactions can increase the possibility of fraud, leaving consumers potentially on the hook for significant amounts of money.

Debit cards don't offer the same protection as credit cards. If your credit card is lost or stolen and someone goes on a shopping spree, you can dispute the charges and you've lost nothing. But if someone steals your debit card and pin, they can immediately extract the cash from your account. You may be out the money for days, or even weeks, while the issue is cleared up.

According to federal regulations, consumers who report debit card fraud within two business days of the loss or theft are only liable for fraudulent charges up to $50. But if 60 days go by from the date the statement listing those charges was mailed out, and you don't notify the bank or financial institution of the problem, you could be liable for any unauthorized transactions afterward. That may include money removed from savings accounts linked to your checking account, and even the full value of any lines of credit associated with the account. Here are a dozen tips to protect yourself:

1. Monitor the account balance daily -- and make sure your computer has up-to-date antivirus and anti-spyware software. "Get in the habit of checking your bank accounts as often as you do the social networking sites," says Greg McBride, senior financial analyst with Bankrate.com, "whether you're looking to make sure payments cleared so you're not overdrawing accounts or monitoring against theft or identity theft."

I look at all of my accounts as part of my morning routine. Another method is to set up account alerts. Have the bank notify you by email if a transaction above a certain amount happens, or your balance drops below certain amount.

2. Watch out for unsecure bank sites. Atul Prakash, a professor of computer science and engineering at the University of Michigan, conducted a 2006 study of the online banking operations of more than 200 institutions, and found 75 percent had at least one design flaw that could make customers vulnerable to cyber thieves.

For example, 55 percent of the sites Prakash studied put contact information and security advice on unsecure pages. When you log in to your bank, the URL should begin with "https" to indicate it's a secure channel -- not "http." "The problem is if I have an unsecure page that's not 'https,' then essentially it could be faked," he says. "It's very easy to make a look-alike site with all the logos, pictures and ads -- but it's not your bank." Another no-no: 28 percent of the sites allowed the use of social security numbers or email addresses for user IDs. This information is easy to guess or discover.

3. Make up fake answers to the personal security questions. Prakash suggests that you create nonsensical answers to login security questions; when it asks for the city where you were born, you could write "broccoli." (Just write down the info and store it securely.) "If you really put the place you were born, that's probably on your Facebook page," he says. "Go with the assumption that all personal information is known."

4. Never respond to an email from your bank asking you to provide security information; such emails are "phishing" scams -- the link provided goes to a fraudulent site set up to collect the information and raid your account. Bookmark your bank's Web site, and always log in from there.

5. Don't use your debit card while traveling, Prakash says, and don't log into your account through a hotel's router -- either wired or wirelessly. "There are ways in which your (connection) can be compromised," he says. "There is a very sophisticated attack which would let them take over your browser, and since they are on your machine at that point, even if you're on a secure channel, they can still peek into your account."

6. Don't put big-ticket purchases on a debit card. "There are a lot of purchases that are just much better suited to credit cards," says McBride. A credit card offers more protection if goods are damaged or defective, because you can refute the charges. I typically charge fixed-amount items of less than $50 to my debit card -- groceries or a small household purchase.

7. Beware of putting gasoline or restaurant bills on a debit. These merchants may freeze your card with a set amount to accommodate additional charges -- such as a big tip for the waitress. The gas station may require you to swipe the card before you fill the tank, so it blocks out a certain amount on your card to cover a full tank -- and then some. See this story for more details.

8. Be sure there is extra padding in your checking account if you debit frequently. "Even something as innocuous as a gasoline purchase could knock you for a loop if you're running the account balance low and a freeze is put on that card by the merchant until the transaction settles," says McBride. "The merchant may put a $75 freeze on the card and it takes two days before the transaction settles. It's really a $25 withdrawal but the frozen $50 could have triggered other overdrafts if you are running your balance really low."

9. Don't use your debit card on e-commerce sites. Use a credit card or Paypal account.

10. Beware of "skimming." This is a technique in which thieves set up equipment that captures the magnetic stripe and keypad information when you input your PIN at ATMs, gas pumps, restaurants or retailers. Consumer Reports, which investigated the scam, says gas stations are prime territory for skimming -- so hit "credit" and sign for the transaction instead of entering a pin. Also use an ATM at a bank instead of a convenience store, because bank ATMs tend to be better monitored.

11. Read the fine print. "Look at the policy the bank has in terms of fraudulent transactions," says Prakash. "Some banks clearly say that even if the account is compromised because someone steals the user ID and password, they will make you whole; others are a little more cagey. The wording is different across different banks."

12. Finally, Prakash advises consumers to designate one computer for online transactions (no casual Internet surfing allowed). "You need to create end-to-end trust and to do that you need a trusted machine and trusted pipe to your bank," he says. "The more things you can keep under control the better it is."

Rate This story

Very Good (117 Ratings)
4/5
Sign-in to rate!

30 Comments

Showing comments 1-5 of 30Next >>
Sort: first to last
  • Yahoo! Finance User - Tuesday, November 24, 2009, 11:47AM ET  Report Abuse

    • Overall: 3/5

    I agree with Cyrus that the advice about protections for debit cards when used as credit cards is misleading. If a Visa or Mastercard debit card is used as a credit card, then the consumer will enjoy the stronger credit card protections. However, I also agree with those readers who point out that it is the policies of Visa and Mastercard that afford these protections - not federal law. As such, Visa and Mastercard can change their policies and rescind this protection, although that is unlikely. However, in spite of that misstep, I still believe the article offers some valuable advice. The other tips are relevant to debit cards simply because that is the primary way people interact with banks and a significant gateway to general bank fraud. There is absolutely nothing wrong in advising people to check their accounts daily and making up fake answers to the bank site security questions is an excellent idea. I think it is good idea not to use debit cards for large purchases made in person or for any internet purchases. Also, so many people get stung by fake bank e-mails that request personal information that this caution bears repeating. A couple of tips the author offered are easy to overlook: (1) make sure https: is in the internet address when logging on to a bank site; and (2) use one computer for banking transactions only and another for surfing the internet. Re: (1) computer security experts have lately sounded alarms about trojans that intercept a consumer communication with a bank as it is being transmitted because some banks do not encrypt the initial log-in screen with SSL, although subsequent screens are encrypted. However, just that one unprotected transaction can be enough for a trojan to hijack the communication meant for the bank, send back fake information that perfectly mimics what the consumer would see on the bank site, and from there, siphon off personal information. Looking for https: in the internet address of bank sites is excellent advice for protection of checking and savings accounts, and by extension, debit cards. Re: (2) the advice to use one dedicated computer for banking transactions is also excellent. The availability of relatively inexpensive netbooks make having a dedicated banking computer in the home more possible. The netbook can be used for banking/finance only and the more powerful desktop/laptop can be used for all other computer activities. Those who enjoy being computer geeks might even want to access bank sites through a different operating system (like Linux) which is not vulnerable to the trojans created for the Windows operating system. Linux can run from a "cd only" setup (called Live CD) or can be run on a computer that is set up to "dual boot" in Windows and Linux. For myself, in addition to using a live Linux CD, I will make sure that there is a default limit on what can be withdrawn daily via my debit card for any account. That is one of several excellent suggestions offered in the comments that should have been in the article.

  • Cas - Monday, November 16, 2009, 12:04PM ET  Report Abuse

    • Overall: 4/5

    Good advice overall; however, keeping track of all those ‘fake’ answers, passwords, logins, etc., is not ease unless you use something like the Passwords Tracker from www.LazyBonesSoftware.com with a build in random password generator, click-n-paste logins and more!

  • DrG - Friday, November 13, 2009, 12:23PM ET  Report Abuse

    • Overall: 2/5

    I don't have a DC. I didn't like the fact that when I did use one, it could be used without a pin number. I use CC for most everything, even bill paying. Love the float and cash-back. I carry an ATM card for emergency cash only.

  • Yahoo! Finance User - Friday, November 13, 2009, 10:51AM ET  Report Abuse

    • Overall: 5/5

    O.K. Laura, how about a column on how to protect us from Government FRAUD? With all the hard earned tax dollars that Mr. O has pumped into corporate America we have a stock market on steroids. Talk about 'fraud." Who ever knew this is what the Prez meant by "spreading the wealth around?" Steal from the working class to give more to the rich investor class. Hey Barack, finally some real 'Hope & Change' that Wall Street can really believe in. Thanks!

  • Yahoo! Finance User - Friday, November 13, 2009, 9:34AM ET  Report Abuse

    • Overall: 4/5

    Gold and Precious metals (DBP) will continue to rise as the dollar slips, but the market in general will also benefit as we work our way out of the recession. We should have a Santa Claus Rally in December. People are buying activision games like crazy and apple will make a serious profit. Even Buffet is pouring capitol back into stocks, look what he just invested in the Railroads? Up and Up and Up and Up.The Dow and S&P should be up 10- 15% by the end of the year. time to make as much as you can before 2012, by then nothing will matter.

Showing comments 1-5 of 30Next >>
The columns, articles, message board posts and any other features provided on Yahoo! Finance are provided for personal finance and investment information and are not to be construed as investment advice. Under no circumstances does the information in this content represent a recommendation to buy, sell or hold any security. The views and opinions expressed in an article or column are the author's own and not necessarily those of Yahoo! and there is no implied endorsement by Yahoo! of any advice or trading strategy.

More From Laura Rowley

Money & Happiness

Discover the secrets to financial happiness. Laura's book offers practical tools and positive strategies to create "the good life" in a meaningful way.

More about Money & Happiness

Learn to identify your values, banish debt, start saving, and investing; plus Laura's favorite online resources.

Order your copy of Money & Happiness today and boost your financial well-being!

More from Yahoo! Sources

  • CNN Money
  • Consumer Reports
  • Kiplinger
  • The Motley Fool
  • Business Week
  • Wall Street Journal

Historical chart data and daily updates provided by Commodity Systems, Inc. (CSI). International historical chart data and daily updates provided by Morningstar, Inc. Fundamental company data provided by Capital IQ. Quotes and other information supplied by independent providers identified on the Yahoo! Finance partner page. Quotes are updated automatically, but will be turned off after 25 minutes of inactivity. Quotes are delayed at least 15 minutes. Real-Time continuous streaming quotes are available through our premium service. You may turn streaming quotes on or off. All information provided "as is" for informational purposes only, not intended for trading purposes or advice. Neither Yahoo! nor any of independent providers is liable for any informational errors, incompleteness, or delays, or for any actions taken in reliance on information contained herein. By accessing the Yahoo! site, you agree not to redistribute the information found therein.

Yahoo! Answers is provided for informational purposes only, and no Q&A is intended for trading or investing purposes. Yahoo! shall not be responsible or liable for the accuracy, usefulness or availability of any Q&A information, and shall not be responsible or liable for any trading or investment decisions based on such information. View Complete Answers Disclaimer.