In light of the previous post, whereby I mentioned that I knew how they got the PIN, I've dug up a news report from Cincinnati, (WCPO...not WKRP) called ATM Scam Targets Debit and ATM Cards.
I've embedded the video report below for your convenience:
Below you'll find a fascinating story by John Deutzman with Fox NY regarding the recent RBS WorldPay breach. Didn't hear of it? That's probably because they issued their press release concerning the breach during the busy Christmas season, December 23rd.
To read about what I thought about it then, visit "Mother of All Hacks Coming? from December 24th.
This incident happened after midnight on November 8th. Now...I know how they got the PINs, (here's a hint, you're on candid camera), so the most intriguing part of this story, at least in my opinion, is the fact that the hackers were able to lift the daily limits on the cards, providing a larger payday. That's the coup de' tat.
To read about what I thought about it then, visit "Mother of All Hacks Coming? from December 24th.
This incident happened after midnight on November 8th. Now...I know how they got the PINs, (here's a hint, you're on candid camera), so the most intriguing part of this story, at least in my opinion, is the fact that the hackers were able to lift the daily limits on the cards, providing a larger payday. That's the coup de' tat.
The coordination and scope of this effort is also amazing even causing the FBI to make comments to that effect. 130 different ATM machines in 49 cities with 100 cards in 30 minutes.
As the story goes, no suspects, only mule drivers, but I think Clive Owens is going to be the guy behind it when they do the movie. Speaking of movies, watch the video on the right if you have the time.
A Fox 5 investigation exposes a worldwide ATM scam that swindled $9 million and possibly jeopardized sensitive information from people around the world. Law enforcement sources told Fox 5 it's one of the most frightening well-coordinated heists they've ever seen. (Watch video report at right.)
Photos from security video obtained by Fox 5 show of a small piece of a huge scam that took place all in one day in a matter of hours. According to the FBI, ATMs from 49 cities were hit -- including Atlanta, Chicago, New York, Montreal, Moscow and Hong Kong.
"We've seen similar attempts to defraud a bank through ATM machines but not, not anywhere near the scale we have here," FBI Agent Ross Rice told Fox 5.
These people in the photos are believed to be "cashers," low-level players, in a scheme devised from some mastermind -- a dangerous computer hacker or hacking ring authorities fear could strike again. Here's how it all came down, according to information Fox obtained from the FBI and law enforcement sources:
The computer system for a company called RBS WorldPay was hacked. One service of the company is the ability for employers to pay employees with the money going directly to a card, called payroll cards, a lot like a debit card that can be used in any ATM. The hacker was able to infiltrate the supposedly secure system and steal the information necessary to duplicate or clone people's ATM cards.
"We've never seen one this well coordinated," the FBI said.
Then shortly after midnight Eastern Time on November 8, the FBI believes that dozens of the so-called cashers were used in a coordinated attack of ATM machines around the world. "Over 130 different ATM machines in 49 cities worldwide were accessed in a 30-minute period on November 8," Agents Rice said. "So you can get an idea of the number of people involved in this and the scope of the operation."
When it was all over, they only used 100 cards but they ripped off $9 million.
The RBS Web site says that card holders will not be responsible for any unauthorized transactions. But there is fear that the hackers might have had access to sensitive information used in identity theft for a potential 1.5 million customers -- including their including Social Security numbers.
"The number of machines that were accessed, the number of cities that were targeted, and the number of people that had to be involved in this is quite significant," Agent Rice said.
Investigators are hoping a break in the case may come from one of the cashers. The theory is they probably were recruited, paid a small fee to be solders in the scam, and might be likely to rat out the people who hired them.
There are millions of people out there these days with these payroll cards. RBS officials say they have sent out letters to anyone who might have been affected. They are also offering one-year credit protection for people whose Social Security number may have been jeopardized by this scam. However, the good news is that it doesn't look like any identity theft has occurred yet.
So far, the FBI has no suspects and has made no arrests in this scam. An attorney in Atlanta has filed a class-action lawsuit against RBS WorldPay for allegedly failing to protect personal information.
RBS WorldPay told Fox 5 the company has hired a security firm to try to figure out what happened and to prevent it from happening again.
VIEW DOCUMENTS:
Snowed in Brits turn to online shopping- Ukash
Ukash, the international provider of online payments with cash, reported a growth in sales of its prepaid vouchers yesterday, as millions of UK workers were homebound after the heavy snowfall turned to shopping and entertainment online.
Year-on-year figures reflect a 79% increase in transactions online made using Ukash compared to the same day in 2008. The first Monday of February is often a poor day for retailers and providers of retail solutions such as Ukash, as the December and January spending hits consumers' pockets. However, the heavy snow fallen in the UK bumped the figures of redemption of Ukash across most retail sectors yesterday. A gaming site specialised in poker games saw a 96% increase in transactions with Ukash, followed closely by the 80% growth registered by a betting site. Bingo also enjoyed a peak yesterday, with a 81% growth, however the greatest surge was registered in VoIP (202%) as the UK turned to internet calling to share the extraordinary weather news with friends and family in the UK and abroad.
Mark Chirnside, CEO of Ukash, puts this excellent performance down to Ukash's wide availability and convenience: "With a large number of us unable to travel, local stores became by far the most convenient stations for the provision of goods yesterday. Four in five Ukash vouchers are acquired from convenience stores in the UK and, with the prospect of being 'homebound' in mind, customers had a perfect excuse to get down to their corner shop and get a convenient and safe way to spend a fun day shopping and playing online alone or with family."
Ukash prepaid vouchers are a safe and convenient way to spend online as they allow customers to pay without having to disclose sensitive financial information. Ukash is available from 275,000 locations throughout Europe and South Africa and also via Vodafone mobiles in the UK. A recent research showed Ukash's average customer in the UK is in full time employment, has a bank account and a credit or debit card but prefers alternative and safer payment methods to transact online.
SAN FRANCISCO (Reuters) - E-commerce in the United States is expected to climb back to last year's levels by 2010 after experiencing slowing growth in 2009 due to the recession, a research group said on Monday.
Online sales in 2010 could reach approximately $176.9 billion, representing 13 percent growth, said Forrester Research in its five-year e-commerce forecast. Last week, the group released data saying the online retail channel was expected to grow 11 percent to $156 billion in 2009, below the 13 percent growth seen in 2008, and the 15 percent growth it had earlier predicted for 2009.
"While there is the possibility of a bearish scenario in which no recovery surfaces in 2009, consumers appear to be enthused about a new president, and government plans to stimulate the economy," the report said. "Furthermore, few recessions have lasted longer than a year in total." The deteriorating U.S. economy led to tepid online sales in 2008 as consumers cut back on all but the most necessary of purchases.
Online retailers faced severe competition from brick-and-mortar establishments that were heavily discounting merchandise, while giants from Amazon.com Inc to eBay Inc have acknowledged the challenging macroeconomic environment that has spooked not only consumers, but financial markets around the globe.
In 2009, greater numbers of affluent customers shifting their purchases from traditional retailers to online outlets will outweigh decreases seen from other customers stemming their spending overall, the report found.
But after an acceleration in 2010, Forrester predicts that growth will slow, with 10 percent, 9 percent, and 8 percent growth expected for 2011, 2012 and 2013, respectively.
"It's just the maturity of the market -- it's reaching its maximum size," Sucharita Mulpuru, author of the report, told Reuters. "Even a few years ago we would have suggested it would be single-digit growth then."
At the same time, e-commerce will pick up a greater piece of overall U.S. retail sales. (Editor's Note: As the Paradigm Shift gathers momentum)
"Despite the deceleration in growth, Web sales are nonetheless expected to be positive as e-commerce continues to capture market share from brick-and-mortar stores," the report found, citing Web shopping's convenience and the ability for consumers to search for low prices.
Whereas the online channel will make up 6 percent of total retail sales in 2009 and 2010, that will increase to 7 percent and 8 percent in 2011 and 2012, respectively.
Online sales in 2010 could reach approximately $176.9 billion, representing 13 percent growth, said Forrester Research in its five-year e-commerce forecast. Last week, the group released data saying the online retail channel was expected to grow 11 percent to $156 billion in 2009, below the 13 percent growth seen in 2008, and the 15 percent growth it had earlier predicted for 2009.
"While there is the possibility of a bearish scenario in which no recovery surfaces in 2009, consumers appear to be enthused about a new president, and government plans to stimulate the economy," the report said. "Furthermore, few recessions have lasted longer than a year in total." The deteriorating U.S. economy led to tepid online sales in 2008 as consumers cut back on all but the most necessary of purchases.
Online retailers faced severe competition from brick-and-mortar establishments that were heavily discounting merchandise, while giants from Amazon.com Inc to eBay Inc have acknowledged the challenging macroeconomic environment that has spooked not only consumers, but financial markets around the globe.
In 2009, greater numbers of affluent customers shifting their purchases from traditional retailers to online outlets will outweigh decreases seen from other customers stemming their spending overall, the report found.
But after an acceleration in 2010, Forrester predicts that growth will slow, with 10 percent, 9 percent, and 8 percent growth expected for 2011, 2012 and 2013, respectively.
"It's just the maturity of the market -- it's reaching its maximum size," Sucharita Mulpuru, author of the report, told Reuters. "Even a few years ago we would have suggested it would be single-digit growth then."
At the same time, e-commerce will pick up a greater piece of overall U.S. retail sales. (Editor's Note: As the Paradigm Shift gathers momentum)
"Despite the deceleration in growth, Web sales are nonetheless expected to be positive as e-commerce continues to capture market share from brick-and-mortar stores," the report found, citing Web shopping's convenience and the ability for consumers to search for low prices.
Whereas the online channel will make up 6 percent of total retail sales in 2009 and 2010, that will increase to 7 percent and 8 percent in 2011 and 2012, respectively.


Visa issues security alert (click pictures to enlarge and enable full viewing)
Source: Merchant Account Blog:
Visa has issued a security alert (relating to the recent Heartland breach?) outlining some specific applications and IP addresses to look out for.
What is unique about this alert is that Visa gave a very specific list of malicious applications to search for on a network/computer, and a specific list of IP’s to block.
This would indicate that Visa has explicitly identified threats, where they are originating from, and these locations are static enough that blocking them would actually do some good...
War Cloning: Homeland Security's Passport Cards Can Be Cloned with $250 Worth of Equipment
You know those new Homeland Security Issued "Passport Cards? Those wallet sized ones that allow American's to travel too and from Mexico and Canada? Well if an Islamic terrorist had $250 bucks, he could drive by your house at 30 mph (or within 2 miles of it) clone it, and use your passport card to travel to and from Mexico and Canada under the guise of being you. Oh, cloning your driver's license is just as easy.
The reason I'm bringing you this story is to provide an example of what hackers are capable of. So let's all wave our contactless cards and NFC enabled phones when they become widely available because they're safe and secure and convenient, (personally, I'm not buyin' it)
What's more disturbing about this story is the fact that it creates a scenario whereby Homeland Security is actually potentially providing the instrument of mass destruction. WarCloning is indeed the right word for this type of hack, as this story suggests the following hypothetical.
You know those new Homeland Security Issued "Passport Cards? Those wallet sized ones that allow American's to travel too and from Mexico and Canada? Well if an Islamic terrorist had $250 bucks, he could drive by your house at 30 mph (or within 2 miles of it) clone it, and use your passport card to travel to and from Mexico and Canada under the guise of being you. Oh, cloning your driver's license is just as easy.
The reason I'm bringing you this story is to provide an example of what hackers are capable of. So let's all wave our contactless cards and NFC enabled phones when they become widely available because they're safe and secure and convenient, (personally, I'm not buyin' it)
What's more disturbing about this story is the fact that it creates a scenario whereby Homeland Security is actually potentially providing the instrument of mass destruction. WarCloning is indeed the right word for this type of hack, as this story suggests the following hypothetical.
After a devastating attack on a major US city, it could be proven that on such and such a day, at such and such a time, you entered the US from Mexico, (your cloned DL and Passport card provide the evidence) and that two days later you purchased 250 pounds of fertilizer (your cloned debit card transaction record provides that proof) went on to rent an industrial van, (proven by your cloned credit card transaction) drove to a specific location, and then...we'll you get the morbidity of my point. You may or may not have alibi's to disprove the "evidence" but even if you did, the investigation was thrown enough off track to allow the true culprit to enter Canada via another passport card, and hop on a plane with a ticket bought online with yet another cloned card and fly to a cave in Pakistan to join his bin-buddies whom we (in fairness, it's only Bin nearly a decade) can't seem to find. Nice job Homeland Security.I've included a video of the act of cloning these cards. Amazing. This was dark reading indeed. Here's the YouTube Video, followed by the excerpts of the story.
Drive-By 'War Cloning' Attack Hacks Electronic Passports, Driver's Licenses
Researcher demonstrates the ease of scanning and cloning new Homeland Security-issued IDs
With a $250 used RFID scanner he purchased on eBay and a low-profile antenna tucked away in his car, a security researcher recently cruised the streets along Fisherman's Wharf in San Francisco, where he captured -- and cloned -- a half-dozen electronic passports within an hour.
Chris Paget, who will demonstrate the privacy risks with these IDs at the Shmoocon hacker confab later this week in Washington, D.C., coined this newest RFID attack "war cloning" given its similarity to war-driving, or wireless sniffing. "War cloning -- it's the new hacker sport," he says.
The security weaknesses of the EPC Gen 2 RFID tags, which lack encryption and true authentication, have been well-known and of concern to privacy advocates for some time. These tags are being used in the new wallet-sized passport cards that the U.S. Department of Homeland Security offers under the new Western Hemisphere Travel Initiative for travel to and from Western Hemisphere countries. The e-cards are aimed at simplifying and speeding up the border-crossing process, providing U.S. Customs and border agents with information on the individual as he or she queues up to inspection booths at the border.
Until now, security researchers for the most part have shied way from hacking away at the new e-passports and e-driver's licenses to illustrate the potential privacy problems because the necessary scanners are expensive -- nearly $3,000 new -- and tough to get. "I found a way to procure equipment on the cheap and repair it and make it do exactly what I wanted it to do," Paget says. (Editor's Note: That's great news, security researchers can't afford equipment, but fraudsters are "well-funded.")
Unlike previous RFID hacks that have been conducted within inches of the targeted ID, Paget's hack can scan RFID tags from 20 feet away. "This is a vicinity versus proximity read," he says. "The passport card is a real radio broadcast, so there's no real limit to the read range. It's conceivable that these things can be tracked from 100 meters -- a couple of miles."
Paget says he was able to drive his car at 30 miles per hour and capture an RFID tag in a matter of seconds. "The software for [copying them] lets you just choose the tag you want to copy, wave a blank tag in front of it, and it writes it out," he says.
Read Full Article at Dark Reading
Payments News: American Express Joins EMVCo As Fourth Owner-Member - February 03, 2009
EMVCo, the EMV standards body jointly owned by JCB International, MasterCard Worldwide and Visa Inc., has announced American Express as its fourth owner-member. According to the organization, "the addition of this latest international payment organisation aligns with EMVCo’s intent to attract further industry participation in the development of the EMV Specifications."
As an established supporter and end-user of EMV technology, American Express has acquired a one-fourth share of EMVCo from the respective holdings of JCB International, MasterCard Worldwide and Visa Inc., and will therefore have an equal interest in the organisation. EMVCo’s management structure has been changed to give American Express representation on the organisation’s Executive Committee and Board of Managers, in addition to equal participation in its working groups.
“EMVCo welcomes American Express as its fourth global payment system member,” said Tad Fordyce, Chairman of the EMVCo Executive Committee and Head of Global Cross Product Platforms at Visa Inc. “American Express will be able to lend expertise at both the technical and management level which will directly support the EMVCo goal to enhance global chip standards, and offer secure and interoperable payments at the point of sale around the world.”
Susan Hillel, Senior Vice President of Global Network Operations at American Express, says: “American Express is delighted to join and become a member of EMVCo. We are committed to driving interoperability in payments and know that our participation in EMVCo will facilitate this for our merchant, issuer and cardmember customers. Involvement by the four major payment organisations will drive secure and interoperable payments globally for transactions made with chip cards by aligning and progressing EMV Specifications. We look forward to working with JCB, MasterCard and Visa on this very critical industry initiative.”
Kazuhiro Matsumoto, member of the EMVCo Executive Committee and Executive Vice President of Global Infrastructure and Technologies at JCB International, comments: “The participation of American Express within EMVCo supports our focus on broadening industry involvement within the organisation and leveraging the experience of all major payment stakeholders. This new member will bring extensive industry knowledge and valuable chip card experience to EMVCo which will considerably benefit the smart card industry as a whole.”
Art Kranzley, member of the EMVCo Executive Committee and Chief Emerging Technology Officer at MasterCard Worldwide, adds: “The existing members of EMVCo recognise the benefits of expanding industry involvement in the ongoing development and support of the EMV Specifications. Achieving global chip standards and interoperability has never been more important as smart card payment technology is rapidly being deployed throughout the world. EMVCo looks forward to having American Express participate as a new owner-member who brings additional market experience and resource to the organisation.”
EMVCo’s growing commitment to increase industry engagement with its activities was demonstrated last year when it announced the launch of a new subscriber service. The programme will provide interested parties with an opportunity to access advanced information regarding revisions to the EMV Specifications and draft documents, and attend an annual user meeting. For further information visit http://www.emvco.com.
About EMVCo
EMVCo LLC was formed in February 1999 by Europay International, MasterCard International and Visa International to manage, maintain and enhance the EMV™ Integrated Circuit Card Specifications for Payment Systems. With the acquisition of Europay by MasterCard in 2002 and JCB Co., Ltd. joining the organisation in 2004, EMVCo is currently operated by JCB International, MasterCard Worldwide and Visa Inc.




