Category
IT Security Research & Digital Policy
Topic
Payment card for refugees
Audience
Local authorities, the media and those interested in digital policy
Reading time
approx. 5 minutes

The payment card for refugees has been a hotly debated topic for years. It is intended to ensure that refugees do not receive cash directly from local authorities, but that all purchases and transactions are carried out exclusively via a prepaid credit card, or that cash can only be withdrawn from cash machines. There is criticism of the payment card; for example, extensive restrictions (on cash withdrawals, online purchases and bank transfers) are criticised, and it is argued that this jeopardises the right to a decent minimum standard of living. For these reasons, the Society for Civil Liberties is taking legal action against the payment card in several cases.

Gradual introduction across the federal states

The payment card for refugees has been in use in every federal state in Germany since May 2024 and is being rolled out on an ongoing basis. The federal states had previously agreed on corresponding minimum requirements. However, the Asylum Seekers’ Benefits Act (AsylbLG) does not set out any specific requirements regarding the functioning or configuration of the payment card. The specific implementation is the responsibility of the federal states, and there are, in some cases, considerable differences. In some federal states, any amount of cash may be withdrawn, whilst in others, a maximum of €50 per month per person is permitted (in some cases with extremely high additional fees for cash withdrawals). In some federal states, online purchases are strictly prohibited, whilst in others they are permitted subject to checks.

Ethical IT security research uncovers flaws in payment card

Back in April 2024, our employees Tim Philipp Schäfers and Niklas Klee took a closer look at the payment card for refugees and the associated apps, and published a 39-page security report on the subject. The report contains findings on vulnerabilities and data protection issues present at the time in the various solutions, which were responsibly reported to the manufacturers. Among other things, it was found that unique identifiers of devices in use (AdvertisingIDs) were being transmitted to big tech companies such as Google or Facebook without consent. Furthermore, there were serious security vulnerabilities, such as XSS (Cross-Site Scripting), in the solutions.

At the time, the report was covered by Netzpolitik.org, golem.de and fragdenstaat.de. There was also a feature on the topic on WDR.

Tim and Niklas also gave a talk in May 2024 at the Chaos Computer Club’s ‘Gulaschprogrammiernacht 22’ in Karlsruhe, where they presented their findings. The full talk can be viewed here: Click here

Vortrag zur Bezahlkarte auf der Gulaschprogrammiernacht

Recent coverage in Kohero magazine

Journalists Jessica Chen and Lucia Junker took a closer look at the implementation of the payment card for refugees in Hamburg. They also interviewed Tim and Niklas about the investigation at the time. As a result, an interview about the payment card – including the shortcomings highlighted at the time – and a report on the payment card in general have recently been published in the migrant and charitable magazine Kohero.

The full interview can be read here (after completing a free login): Click here

There is also a more comprehensive report on the payment card (in Hamburg) and the criticism levelled at it (after free login) available to read: Click here

“At Mint Secure, we are delighted to be making a contribution to the security of key IT systems and will continue to take a constructively critical approach to digital policy topics through our ethical IT security research.”
Mint Secure GmbH

Interview im Kohero Magazin zur Bezahlkarte

How Mint Secure supports you in this

Independent, ethical security research is particularly needed for sensitive, socially relevant IT systems such as the payment card for refugees. We support this with the following services:

🔍

Responsible security research

We identify vulnerabilities in apps and systems and report them to the manufacturers in accordance with the principles of Responsible Disclosure.

📱

App & API security audits

We test apps and interfaces used by public bodies for tracking, data protection and security vulnerabilities such as XSS.

🏛️

Advice for local authorities and public bodies

We advise local authorities and government bodies on the secure and data-protection-compliant design of digital social benefits systems.

Want to get started? We offer a free initial consultation.
Get in touch now.

Conclusion

The payment card for refugees serves as a prime example of how important independent IT security research is for projects involving sensitive digital policy issues. The vulnerabilities uncovered in 2024 and the non-consensual tracking via advertising IDs make it clear that even systems with a public mandate must be carefully scrutinised.

The ongoing media and legal debate surrounding the payment card also shows that technical and societal issues are closely intertwined in such projects.

Mint Secure continues to address digital policy topics through ethical IT security research.
Please get in touch.