Cracker Gains Access to 2.2 Million Credit Cards
Doctor Sbaitso writes "CNN reports that a hacker bypassed the security system of a company that processes credit card transactions and gained access to approximately 2.2 million Visa and MasterCard credit cards. Fortunately, none of them seem to have been used fraudulently."
2.2 million...it will be interesting to see what happends when who ever did this starts to sell them in bulk. Who is going to be responsible? The Credit Card companies or the site that got hosed?
Should prove interesting as these numbers start getting used. 2.2 is a little large of a block to just re-issue.
Neck_of_the_Woods
#/usr/local/surf/glassy/overhead
Remember, Credit Cards companies use neural networks to analyse transactions and decide whether or not they may be faulty, and the success-rate of these babies is higher than you may suspect (okay, I don't have a web-link, I read it in a pop-sci book on maths, biology and AI). So you may be short a few dollars, which isn't good (don't get me wrong), but unless you normally spend $hitload$ of money, they won't be able to buy a Ferrari or anything (mind you, if they only took a few cents from each credit card account, they COULD buy a Ferrari ...)
This sig intentionally left bla... dammit!
Who's got the whiteout?
Nice informative article. No mention of which credit card processor this was. It'd be nice to know if it's one that one of my clients uses. Anyone know the identity of the victim?
SONY. Because caucasians are just too damn tall.
I do notice that sometimes, very rarely though, that sites will ask for that extra three digit code on the back of the card, to verify that you do in fact have the card in your hand. This the same concept as a PIN and I don't see why more web sites aren't doing it. It's not like they have to completely revamp their way of accepting credit cards, it should be a very simple fix.
Makes me want to go back to barder. Do you think ThinkGeek would accept two dead chickens and a half wheel of gouda for one of those mini tanks with the camera?
this report says 5 million cards
1 7/ rtr881826.html
http://www.forbes.com/markets/newswire/2003/02/
Of course, they don't know. They won't know for a while. But the answer is Nothing Stolen, and the answer will always be Nothing Stolen.
Credit card companies are like insurance companies, it's all about playing the odds, and statistics, and consumer behavioural models. Personally I've stopped trusting them a long time ago. While the public meme is that credit card theft is on the rise due to Internet transactions, I really wonder sometimes. As seen with other examples, the Internet is actually becoming an invaluable tool for revealing nefarious activity (patterns of activity that is) that would have been otherwise obfuscated by natural physical barriers. The media are hardly reliably objective in this sense.
If Jesus wants me it knows where to find me.
Inquiring minds want to know...
Well, I can imagine that if EVERYONE in the world got a list of a few million credit card numbers, you would suddenly see an awful lot of fraudulent purchases! I for one would be tempted, not to do something to get me in trouble (well they can try), but more likely a visit to my local net cafe to send some presents. Let's see:
- A full compendium of all O'Reilly Free software books, Debian DVD sets and an X-Box with the LinuxBios Mod installed for Bill Gates, Steve Ballmer, Scott McNeilly, Michael Dell and anyone else on those lines who took my fancy and whose address I could find. I might even send one to every elected official in my country while I'm at it!
- Amazon's entire porn collection (they have one I presume) for every censor on the planet.
- A cross sending of every spammers products I could come up with to all the other spammers.
God only knows what else could take my fancy, and god only knows how many orders would actually be filled. Heaven forbid anyone found a well known persons card in there, say Jack Valenti, I think he would find himself making some massive (or massive numbers of) donations to Mplayer, Freenet and any projects people could find which he campagins against.Do you REALLY think that people would hear on the radio about the 2.2 million credit card numbers 100 million people just recieved and think, "oooooooh they're gonna catch me if I touch them!"
The far more probable outcome is that an email of about 4 Mb (2,200,000 CC# * 20 bytes @ 90% compression) sent to 100 million people (or whatever the latest net use figures are) would be stopped at most ISPs very, very, very quickly as it would be lauching a large spam based DDOS against them (unless I underestimate the backbone out there). Sure it would get through to a lot of people, but unless it gets through to 10+% of hotmail or something similar, most users will have the fear you describe put into them.
A far more interesting prospect would be if instead of plain e-mailing the list around, a virus was used to propagate the data covertly by infecting web and/or email servers. If you get a web-server, you get it to gather the list and take part in attacking more hosts and passing it onto them, you also get it to add a link to every page at the trigger time so all visitors to that site gain access to the list. If you get an e-mail server, you just need to get the data there once and explode it out to all local mailboxes at the same trigger time (aswell as using the host to propagate). Then it comes down to a question of trying to balance the timings to maximise the number of boxes unchecked by the time of revelation.
Of course is there anything to stop the crackers from just dumping the data into all the P2P networks and letting it spread from there?
Finally I have to point out that I have no interest in obtaining these numbers (or any others, except my own :-) and I am certainly not advocating credit card fraud. Just saying that if an opportunity like you described (every email box got the list) came my way, I would be very tempted to try and enjoy myself with some humourous (to me) exploits from a safe place and that there would probably be tens or hundreds of thousands of other following suit. Damages would rack up pretty quickly.
Never underestimate the dark side of the Source
Wells Fargo Bank cancelled my debit/Visa card with no notice.. Why? Because I purchased groceries in Los Angeles, and then there was a $300 purchase in the mid west for a plane ticket a few hours later.
:)
Unfortunately, the $300 ticket was to get my 13 year old step-daughter on a plane to see her dad. We didn't know til we got to the airport and Delta told us my card was stolen..
I pulled out my card, and my ID, and showed it to them.. Didn't matter.. I called the bank. They had no record of who did it, only that it was reported as stolen.
Took me 8 hours on the phones with the bank, airline, and every vendor I had bought from in the surrounding days to find out what happened.
When the airline called to verify the card, the bank took the fact that I was buying a ticket for her to be fraud, and cancelled my card immediately.
I went to the bank to get it fixed. They said they tried to contact me. They had my correct number on file (my cell), but said it was disconnected. I had them call my cell from their desk. Amazingly enough, it rang, and I answered.
I've had banks call me before to verify transactions. I have no problem with that. But, lying about it pisses me off.
I wonder how badly they'd handle me on a road trip. I drive from Florida to California and back on a semi-regular basis.. It takes me three days, with very little sleep. That would probably get the card cancelled too.. I'd hate to be stuck in Kent Texas with no gas and a cancelled credit card, because they thought I had traveled too far.
I had a whole stack of returned items, and a whole lot of merchants to apologize to for the bank's error. I never received an apology from the bank.
A month later (a week before xmas), they accidently closed my bank account. I didn't find out til the ATM took my new card.. Their system said there was fraudulent activity. Another bank error. They put all my funds on hold til Jan 6. Good thing I have friends who would loan me money over Christmas. It really sucks to ask your friends to buy everything.. But, they all got paid back after I got my money back.
Every bill check I had sent out previous got bounced. Wells Fargo *ALSO* charged me $25 per check for NSF, even though the funds were in the account, but they erroniously put on fraud hold by them.
You wouldn't believe how pissed I was when I got to the bank. I was polite at first.. They continued to tell me how they were keeping my money.. So, I got louder.. They threatened to call the cops. I told them to. I *WANTED* a cop to hear them saying that they made a mistake and took my money, and wouldn't give it to me.
The bank security were the only nice people working there. One of the guards told me how they screwed him over too, so he was completely sympathetic. He was just standing around to make sure I didn't get physically violent. No problem there, I don't get physically violent, he doesn't have to do anything but stand there.
Warning! Never Use Wells Fargo Bank!
I finally got the second set of NSF fees dropped after a few hours of screaming.. Hopefully the customers who overheard the incident had second thoughts of keeping their account at Wells Fargo.
[Rant Mode Off]
I'm now using a nice small bank, that doesn't have the same problems. I told them all about it when I opened my new account. They had heard similiar stories before about them. I'm on a first name basis with the new bank, and they love me.
Serious? Seriousness is well above my pay grade.
They dont actually say somebody hacked into their network from the internet.
Manipulate the moderator system! Mod someone as "overrated" today.