Slashdot Mirror


Attackers Steal $12.7M In Massive ATM Heist (mainichi.jp)

Within two hours $12.7 million in cash was stolen from 1,400 ATMs located at convenience stores all across Japan, investigators announced Sunday. An anonymous reader quotes a Japanese newspaper: Police suspect that the cash was withdrawn at ATMs using counterfeit credit cards containing account information leaked from a South African bank. Japanese police will work with South African authorities through the International Criminal Police Organization to look into the major theft, including how credit card information was leaked, the sources said.
Over the two hours attackers withdrew the equivalent of $907 in 14,000 different transactions.

41 of 75 comments (clear)

  1. Re:$907? by JustOK · · Score: 1

    Clarify your terrible editing

    What the hell does that even mean?

    --
    rewriting history since 2109
  2. Re:$907? by TigerPlish · · Score: 1

    Clarify your terrible reading comprehension:

    From TFS:

    Over the two hours attackers withdrew the equivalent of $907 in 14,000 different transactions.

    $907 x 14,000 = 12,698,000

    --
    The "Civilized World" jumped the shark ca. 1973.
  3. Re:$907? by BarbaraHudson · · Score: 1

    Come on, it's perfectly understandable as $907 * 14,000 transactions. There's pedantry and then there's whining for the sake of whining.

    --
    "Transparent" is a shit show that trades on every stereotype going. A man in drag is NOT a transsexual.
  4. Re: Hmm by Anonymous Coward · · Score: 1

    From TFA,
    In each of the approximately 14,000 transactions, the maximum amount of 100,000 yen was withdrawn from Seven Bank ATMs using the fake credit cards, according to the sources.

    Guess how much 100,000 yen is in dollars...

  5. Re:Bullcrap. 14000 transactions in two hours... by onepoint · · Score: 4, Interesting

    I'm thinking that it's all done via mule teams
    so 1400 machines and 14000 transactions = 10 transactions per machine
    each transaction should take start to finish 2.5 minutes so we are looking
    about 30 minutes for 10 transactions giving time for who knows what.

    From this point, I am guessing 3 machines per person ( 30 min to take and 10 min to next machine )
    so... 1400 / 3 = 467 members ( round up slightly for time losses so jump to 500 mules )

    I am going to state that in Japan, it's doable, they got the team work.

    How to discover the team, reverse engineer all bank searches for atm
    machines, bet certain group patterns show up.

    --
    if you see me, smile and say hello.
  6. Re: $907? by breakermelvin · · Score: 1

    14,000 x $907 = $12.7m So where do you join this gang of 1400 fantastically well coordinated thieves?

  7. Re: $907? by ShanghaiBill · · Score: 5, Informative

    14,000 x $907 = $12.7m So where do you join this gang of 1400 fantastically well coordinated thieves?

    $907 is exactly 100,000 Yen, which is the transaction limit.

  8. This proves them wrong by JustAnotherOldGuy · · Score: 1

    And they say crime doesn't pay.

    --
    Just cruising through this digital world at 33 1/3 rpm...
  9. Re:Too many people by Anonymous Coward · · Score: 1

    The mules do not know the guys at the top of the hierarchy. The guys who got most of the cash will not appear on any footage. At best the police will catch some of the idiots who thought it was easy cash and some of their handlers.

  10. Re:$907? by JustAnotherOldGuy · · Score: 3, Funny

    What the hell does that even mean?

    It means he is unable to comprehend simple sentences or basic mathematics.

    --
    Just cruising through this digital world at 33 1/3 rpm...
  11. Re:Bullcrap. 14000 transactions in two hours... by TechyImmigrant · · Score: 2

    A team that big wouldn't work.
    Just offer anonymity, immunity and a reward > $12,000,000/467.

    Only the first to squeal gets the offer.
     

    --
    I should use this sig to advertise my book ISBN-13 : 978-1501515132.
  12. Massive ATM Heist? by Gravis+Zero · · Score: 4, Funny

    Why did they put $12.7M in one massive ATM? come on, that's just stupid! #OnlyReadTheHeadline

    --
    Anons need not reply. Questions end with a question mark.
  13. Re:$907? by Hognoxious · · Score: 4, Informative

    To be fair, the sentence probably should have contained the word "each".

    --
    Confucius say, "Find worm in apple - bad. Find half a worm - worse."
  14. typical! by Gravis+Zero · · Score: 1

    When are these fools going to learn to only deploy massless ATMs? #OnlyReadTheHeadline

    --
    Anons need not reply. Questions end with a question mark.
  15. Re: $907? by Type44Q · · Score: 1

    So where do you join this gang of 1400 fantastically well coordinated thieves?

    Not sure how much good it'll do you but I suppose you can start here.

  16. Re:Bullcrap. 14000 transactions in two hours... by sjames · · Score: 1

    And all he knows is a few vague details of his contact and that he will die shortly for squeeling.

  17. Crowd sourcing? by Camel+Pilot · · Score: 1

    Crowd sourcing white collar crime.

  18. Re:Bullcrap. 14000 transactions in two hours... by lgw · · Score: 4, Insightful

    It was in fact a team of "over 100". Japan is Japan.

    Interesting juxtaposition of stories on the Slashdot front page today. Guy discovers a vulnerability, tells the police, gets busted, his computers taken, and a 15 month suspended sentence. Guy discovers a vulnerability, goes black hat, steals $12 M in one day.

    Kinda hard to miss the incentive system currently in place.

    --
    Socialism: a lie told by totalitarians and believed by fools.
  19. Re:Bullcrap. 14000 transactions in two hours... by onepoint · · Score: 2

    Dude, it's the Japanese Mafia, they don't have rat's, they got it down pat to have no issues from everything I've ever read.

    --
    if you see me, smile and say hello.
  20. Re:$907? by JustAnotherOldGuy · · Score: 2

    To be fair, the sentence probably should have contained the word "each".

    Perhaps, but I think it would be pretty obvious to anyone who thought about it for a moment.

    --
    Just cruising through this digital world at 33 1/3 rpm...
  21. Re: $907? by Anonymous Coward · · Score: 1

    Pick any Yakuza branch. The police won't trouble you but the other branches will.

  22. Re:How much is the Jap $ compared to say Amer $? by Buchenskjoll · · Score: 1

    Japanese dollars? Seriously? Have you ever heard of currencies that are not dollars? Such as yen?

    --
    -- Make America hate again!
  23. Re:Bullcrap. 14000 transactions in two hours... by esperto · · Score: 1

    ATM heist level asian!

    I bet it was done by half that number of people and they did it while playing some dance game.

  24. Re: $907? by rednip · · Score: 4, Informative

    I suspect that each thief used multiple accounts until each of the ATMs was out of money, then moved to the next one. Perhaps 10 or twenty large withdraws each one might take 10 to 20 minutes. Five to ten minutes to get to the next ATM would give four to eight 'sessions' over two hours, so I'd guess that each one worked 40 to 160 transactions, lets say 100 each for lack of better data. Meaning about 140 crooks for the 'back of napkin estimate', I'm no expert on the Yakuza, but that number seems really 'doable'.

    --
    The force that blew the Big Bang continues to accelerate.
  25. Limits by manu0601 · · Score: 1

    I wonder why it did not hit any overdraft limit at the stolen account.

    1. Re:Limits by rtb61 · · Score: 1

      The whole operations positively screams inside job. That many transactions without failure in that short time, it means all those accounts were specifically chosen. No alarms, means those account were specifically chosen, and chosen well in advance. There will be a hack left in the system to hide the hackers and not expose those who had full access. Simply over the top operation, they might have trouble legally proving who did it but they will be able to work out who did it in short order and those on foot will be caught up in security camera footage, too many locations to escape repeated detection.

      --
      Chaos - everything, everywhere, everywhen
    2. Re: Limits by ytene · · Score: 1

      Whilst I agree with your first statement, in that some knowledge of how to create a fake card would be required, the rest of your theory may not follow. In the UK, the big retail supermarkets do not validate every card transaction with the issuing bank in real time. Instead they sample a smaller number of transactions through their trading day, then batch and bulk submit the majority of transactions every few days. Obviously they can keep a history of card numbers previously used successfully and may use historical transaction data to decide which cards to trust.

      They do this because banks charge fees per transaction. The system works for the retailers because the amount of fraud they suffer is less than the reduction in fees they are charged by the banks.

      The OP and article mention that the accounts were South African and used in Japan. This strikes me as exactly the sort of scenario where the chain of processing agents would attach fees, including currency conversion. With everyone taking their cut, you can understand how there would be an incentive to minimize those fees. So maybe another way of describing this heist would be to say that the card issuer and processing banks might have been stung by their own greed.

    3. Re: Limits by rtb61 · · Score: 1

      You have a large number of transaction targeted at a foreign country from a questionable country with low income, where the majority of credit card holders will simply not be able do maximum withdrawals. So those credit cards details were filtered for success. So long term planning and analysis of account details. Statistically speaking based upon the country of origin most of those card numbers should have failed a maximum withdrawal and quite a few should have trigged alarms for out of country, irregular transactions and that does not include the random statistic of credit cards already at or near their limit. That upon the basis that every attempt succeeded. Percentages and statistics indicate a high level inside job.

      --
      Chaos - everything, everywhere, everywhen
  26. Re: $907? by haruchai · · Score: 1

    My desk lamp sits on the floor, you insensitive clod!!

    --
    Pain is merely failure leaving the body
  27. Re: Yakuza, maybe... by EEPROMS · · Score: 1

    never has this [WOOOSH] award been so deserving. The act of burning the CDR was "symbolic" in that it showed how a CDR can be easily damaged thus removing the backup as a viable option. The original poster was correct though, the Japanese are seen as the gods of technology but when it comes to software and security you would think their servers were setup by the dumbest IT guy they could find.

  28. Re:Hmm by wwalker · · Score: 1

    Wow, Slashdot. So my comment gets downvoted *twice* to "flamebate" and then a comment "To be fair, the sentence probably should have contained the word "each"." from a different user gets upvoted to +5 (Informative). What am I missing?

  29. Re:$907? by Hognoxious · · Score: 1

    If you have to analyse it, it's bad journalism.

    --
    Confucius say, "Find worm in apple - bad. Find half a worm - worse."
  30. Re:$907? by stealth_finger · · Score: 1

    To be fair, the sentence probably should have contained the word "each".

    Perhaps, but I think it would be pretty obvious to anyone who thought about it for a moment.

    Only if you've read the previous summary "Over the two hours attackers withdrew the equivalent of $907 in 14,000 different transactions." on it's own says exactly that. There are a bunch of ways to say what they meant but that's not one of them.

    --
    Wanna buy a shirt?
    https://www.redbubble.com/people/stealthfinger/shop?asc=u
  31. Re: $907? by stealth_finger · · Score: 1

    My desk lamp sits on the floor, you insensitive clod!!

    Is it not then a floor lamp?

    --
    Wanna buy a shirt?
    https://www.redbubble.com/people/stealthfinger/shop?asc=u
  32. Re:Hmm by stealth_finger · · Score: 2

    Wow, Slashdot. So my comment gets downvoted *twice* to "flamebate" and then a comment "To be fair, the sentence probably should have contained the word "each"." from a different user gets upvoted to +5 (Informative). What am I missing?

    A snappy username?

    --
    Wanna buy a shirt?
    https://www.redbubble.com/people/stealthfinger/shop?asc=u
  33. Re: $907? by haruchai · · Score: 1

    My floor IS my desk, you insensitive clod!!

    --
    Pain is merely failure leaving the body
  34. Re:$907? by JustAnotherOldGuy · · Score: 2

    Only if you've read the previous summary "Over the two hours attackers withdrew the equivalent of $907 in 14,000 different transactions."

    It was a 5-sentence summary. Who reads the last line without reading the first few sentences?

    The last line may have been a little clumsy on its own but if that's all a person can be bothered to read then they deserve to be confused.

    --
    Just cruising through this digital world at 33 1/3 rpm...
  35. Re:$907? by stealth_finger · · Score: 1

    Only if you've read the previous summary "Over the two hours attackers withdrew the equivalent of $907 in 14,000 different transactions."

    It was a 5-sentence summary. Who reads the last line without reading the first few sentences?

    The last line may have been a little clumsy on its own but if that's all a person can be bothered to read then they deserve to be confused.

    That is true. What is also true is that sentence is badly written.

    --
    Wanna buy a shirt?
    https://www.redbubble.com/people/stealthfinger/shop?asc=u
  36. Re:$907? by JustAnotherOldGuy · · Score: 1

    That is true. What is also true is that sentence is badly written.

    Yes, but that's a long way from being incomprehensible, as the original AC seemed to think, with his "Clarify your terrible editing" comment. Believe me, if you're looking for truly terrible editing you can find lots of more egregious examples in many of the other story summaries.

    Poorly written? Yes.
    Still comprehensible? Yes.

    One doesn't make up for the other, but it's not something that'll keep me awake at night.

    --
    Just cruising through this digital world at 33 1/3 rpm...
  37. Is this another hoax? by martinfb · · Score: 1

    How is it possible to withdraw $907 from an ATM every 1.9 seconds?! How is it possible to withdraw anything from an ATM every 1.9 seconds unless there are thousands working together?! Or, was it all done as e-transfers to another account? Something is amiss: facts are missing, or this is another hoax.

    --


    Self-importance and self-indulgence is the root of ALL evil.
  38. Re:Bullcrap. 14000 transactions in two hours... by pavelthesecond · · Score: 1

    Japan's law system does not have the concept of plea-bargains so there really is no incentive to squeal.