Skip to content

EMV debit card payments are secure

Published on:

Debit card payments in the Netherlands remain secure. Dutch banks are familiar with the University of Cambridge publication “Chip and Skim: cloning EMV Cards with the pre-play attack”, which builds on earlier research from 2012. The university describes a complex attack in which card data is collected for later misuse. Media reports incorrectly suggest that this makes EMV debit card payments insecure. Dutch banks already took measures against this attack in 2012.

Hand holding a Dutch debit card above a payment terminal to make contactless payment (NFC payment) at a PIN terminal.

The attack described by the University of Cambridge depends in part on being able to predict a random number generated by a payment terminal or ATM. If that number cannot be predicted, and is therefore genuinely random, the attack cannot be carried out. The random numbers generated by Dutch terminals cannot be predicted, so this attack cannot succeed in the Netherlands.

Following the earlier publication, Dutch banks carried out an inventory in 2012 to identify payment terminals and ATMs using a weak random number generator. The analysis found that Dutch payment terminals and ATMs did not use weak random number generators.

The university now shows that the attack is easier to carry out in practice if the software of the payment terminal or ATM, or messages in the network, can be manipulated. To support their theory, the researchers refer to terminals that were manipulated in practice, including incidents in the United Kingdom. Additional measures were also taken against this in the Netherlands following the 2012 publication.

Neither component of the attack can occur in the Netherlands. Debit card payments remain secure. Banks advise customers to check their statements regularly and to contact their bank if they do not recognise a debit.

Related articles