US Chip Cards Are Being Compromised In the Millions (threatpost.com)
According to a study from Gemini Advisory, some 60 million U.S. cards were compromised in the past 12 months. "Of those, 93 percent were EMV chip-enabled," reports Threatpost. "Also, crucially, 75 percent, or 45.8 million, were records stolen from in-person transactions." From the report: These were likely compromised through card-skimming malware and point-of-sale (POS) breaches at establishments like retailers, hotels and restaurants, the likes of which continue to make headlines. Further results show that the U.S. leads the rest of the world in the total amount of compromised EMV payment cards by a massive 37.3 million records. In the past 12 months, about 15.9 million compromised non-U.S. payment cards were posted for sale on the underground, split between 11.3 million card-not-present (online transaction) records and 4.6 million card-present records, of which 4.3 million were EMV enabled. This means that the theft level of EMV-enabled card data in the U.S. is 868 percent higher than the rest of the world combined.
The reason for this state of affairs, according to Gemini, is the lack of U.S. merchant compliance -- too many of them still use the mag-stripe function at PoS terminals. Gemini also said that card-present data "is also collected via a more manual method by skimmer groups, who are utilizing custom made hardware known as 'shimmers' to record and exfiltrate data from ATMs and POS systems. The firm also found that while most large U.S. merchants have fully transitioned to EMV, gas pump terminals and small/medium size businesses are emerging as the main targets for cybercriminals going forward.
The reason for this state of affairs, according to Gemini, is the lack of U.S. merchant compliance -- too many of them still use the mag-stripe function at PoS terminals. Gemini also said that card-present data "is also collected via a more manual method by skimmer groups, who are utilizing custom made hardware known as 'shimmers' to record and exfiltrate data from ATMs and POS systems. The firm also found that while most large U.S. merchants have fully transitioned to EMV, gas pump terminals and small/medium size businesses are emerging as the main targets for cybercriminals going forward.
too many of them still use the mag-stripe function
If this is mostly happening via the old magnetic strip than what does the chip even have to do with this story?
So to get this straight, you get a plastic card, it supports both the newfangled way and the old-and-busted way (or else people would be up in arms that it wasn't compatible with 100% of readers). By the way, the new hotness is just the old version plus a transaction-unique cryptographic token. Now, when this is deployed, people figure out -- they skim the new way and then use it to create mag-stripe cards that can be used only at places that don't require a chip. But somehow this is a problem with the chip cards?
Nooooo, it's a problem with places that don't require a chip. We've known since the 80s that you can copy a magnetic strip with a 2-tape boombox (seriously, it will work).
TLDR: There's nothing wrong with the chip cards themselves. But there is something wrong with merchants that haven't upgraded to EMV, and definitely something wrong with /. editors that write a completely ass-backwards headline.
sigh. I'd like to type in pages but I won't.
long story short, I got a text from wells saying they thought something was 'up' with some purchases. I never check sms (I use email and ignore sms) but I later found that text and called wells to check if it was real. it was real and there were thousands of dollars of charges I didn't make. I never lost my card and it was never out of my posession.
I called wells and we went thru the charges. I told them which were mine and which were unknown to me. I thought that was it and waited to hear back. weeks later, I get a letter in the mail from them saying that they 'investigated' it and since the card was never lost and it was a CHIP BASED CARD, it could NOT BE THEIR FAULT and I was told I had to pay the thousands of dollars of charges!
I was shocked. I was a member of that bank for over 20 years (yeah, I know, I should have left years ago when wells first had issues reported against them).
the weeks that they let it sit were weeks that evidence was starting to fade away (video 'tapes' being recycled at stores, etc). I think that was also part of wells' plan, to delay me and make me miss some deadlines.
I forced them to re-open the 'closed' case and I filed a police report. I was not asked to at first, but when I went to the bank in person and made an issue of this, they asked that I make a formal police report, which I then did.
get this: one week later, I get letters in the mail from the local court system. they caught 2 people and I was informed that sentencing was going to happen in 1 week and I was allowed to attend, if I wanted. (I suspect that the forged card had my name on it or receipts from stores had my name on it).
here's the kicker: it took ALL OF THIS in order to convince my bank that it was not me. their line, all along was 'it was a chip card and it never left your possesion, in your own words, and chip cards are PERFECT, so pay up, it was you!'. that was their line and until I showed them court papers, they would not give in.
tell everyone you know about this. the chip cards are less than useless in the US and banks are still putting their fingers in their ears and saying 'I cant hear you, its still your fault, pay up!'.
their security system is at fault and yet they blame us.
it took me MONTHS to get this all cleared out. did I get anything for my time? no. of course not.
wells fargo can eat shit and die. anyone still with them should leave immediately. I was a 20+ year member and they threw me under the bus for a few thousand dollars. they don't deserve to have a single customer. please leave if you are with them.
and be very careful with your 'chip' card. there's nothing secure about it. the thieves have it all worked out already ;(
--
"It is now safe to switch off your computer."