Showing posts with label hack. Show all posts
Showing posts with label hack. Show all posts

Thursday, August 7, 2008

Shocking Internet Hack

Posted by Mark Brousseau

An interesting article from newsday.com about the incredible scope of a recent Internet hack case:

Feds astounded by volume, scope of Internet hack case
BY KEIKO MORRIS
mailto:keiko.morris@newsday.com?subject=Newsday.com
August 7, 2008

The sheer volume of the credit and debit card numbers stolen was astounding as was the far-flung cast of multinational characters in one of the largest Internet hacking and fraud cases federal prosecutors say they've seen in this country.

And while many credit card users are protected from full or partial liability, the scope of the impact of the mammoth case that snagged 11 people in the heist of more than 40 million card numbers is unknown.

For retailers, banks and credit card companies, Tuesday's announcement by federal prosecutors that they had unraveled a case stretching back years, highlighted the constant battle against Internet criminals. And although most consumers won't bear the burden immediately, the price of Internet fraud to banks and retailers could end up costing customers in the long run, technology security experts say.

"... The overall cost is high and you can bet your bottom dollar that that cost will get passed on to us, Joe Average card holder," said Ed Moyle, manager at CTG, an Internet technology firm in Amherst, N.H.

The unveiling of the ring and the numerous charges, including fraud and identity theft, was reason for retailers to rejoice, industry experts said. The conspiracy, allegedly led by Albert "Segvec" Gonzalez, 27, of Miami, hit some of the biggest retailers, including TJX Cos., BJ's Wholesale Club, OfficeMax, DSW and Barnes & Noble, among others."

This was a very targeted attack on our industry," said Scott Krugman, spokesman for the National Retail Federation. "It took a very sophisticated network to do this."

The incidents in which the defendants -- hailing from Belarus and China and Ukraine -- found wireless access points to steal credit and debit card numbers date to 2003. TJX Cos. Inc. based in Framingham, Mass., discovered its computer system allegedly had been attacked by the defendants in 2006. Shoe retailer DSW was hit in 2005. Most of the major credit card companies and banks contacted declined to comment about the case specifically but said they know of the investigation and they have procedures to secure information. For card issuers, the cost to reissue cards is significant and, eventually will get passed down to consumers, Moyle said.

"The sheer number of retailers attacked by these cyber criminals demonstrates the much broader challenges in protecting sensitive customer data from this increasing threat," Sherry Lang, a TJX spokeswoman, said in a statement. "... Broader action beyond retailers alone is required to protect consumer data. Banks and the U.S. payment card industry must join retailers and work together."

Technology security experts said retailers and credit card companies fight a constant battle against cyber crimes and have made strides over the years to comply with technical standards set by the PCI Security Standards Council, a group founded by five of the major credit card companies, to protect information systems.Retailers worry more about their credibility with consumers and their confidence in using the electronic systems, said Brit Beemer, chairman of the market research firm America's Research Group.

The idea that more than 40 million card numbers were stolen from major national chains will make consumers wary, but both retail and technology security experts said they were skeptical the case will change the way consumers used their credit or debit cards.

Both experts and prosecutors said consumers should check their accounts as well as their credit reports and set up fraud alerts if they believe their information has been stolen. Consumers face the hassle of requesting new cards or accounts but institutions' zero-liability policies mean that consumers won't suffer the losses.

"They have zero-liability protection so that definitely helps them get over those fears associated with data breaches," said Bruce Cundiff, director of payments research at Javelin Strategy & research in San Francisco.

What do you think is the solution to these types of hacks?

Post your comment below.

Monday, July 7, 2008

ATM Hack Reveals Security Woes

Posted by Mark Brousseau

An interesting article from the Associated Press about ATM security challenges:

Citibank ATM breach reveals PIN security problems
By JORDAN ROBERTSON
The Associated PressTuesday, July 1, 2008; 4:39 PM

SAN JOSE, Calif. -- Hackers broke into Citibank's network of ATMs inside 7-Eleven stores and stole customers' PIN codes, according to recent court filings that revealed a disturbing security hole in the most sensitive part of a banking record.

The scam netted the alleged identity thieves millions of dollars. But more importantly for consumers, it indicates criminals were able to access PINs -- the numeric passwords that theoretically are among the most closely guarded elements of banking transactions -- by attacking the back-end computers responsible for approving the cash withdrawals.

The case against three people in U.S. District Court for the Southern District of New York highlights a significant problem.

Hackers are targeting the ATM system's infrastructure, which is increasingly built on Microsoft Corp.'s Windows operating system and allows machines to be remotely diagnosed and repaired over the Internet. And despite industry standards that call for protecting PINs with strong encryption -- which means encoding them to cloak them to outsiders -- some ATM operators apparently aren't properly doing that. The PINs seem to be leaking while in transit between the automated teller machines and the computers that process the transactions.

"PINs were supposed be sacrosanct _ what this shows is that PINs aren't always encrypted like they're supposed to be," said Avivah Litan, a security analyst with the Gartner research firm. "The banks need much better fraud detection systems and much better authentication."

It's unclear how many Citibank customers were affected by the breach, which extended at least from October 2007 to March of this year and was first reported by technology news Web site Wired.com. The bank has nearly 5,700 Citibank-branded ATMs inside 7-Eleven Inc. stores throughout the U.S., but it doesn't own or operate any of them.

That responsibility falls on two companies: Houston-based Cardtronics Inc., which owns all the machines but only operates some, and Brookfield, Wis.-based Fiserv Inc., which operates the others.

A critical issue in the investigation is how the hackers infiltrated the system, a question that still hasn't been answered publicly.

All that's known is they broke into the ATM network through a server at a third-party processor, which means they probably didn't have to touch the ATMs at all to pull off the heist.

They could have gained administrative access to the machines -- which means they had carte blanche to grab information -- through a flaw in the network or by figuring out those computers' passwords. Or it's possible they installed a piece of malicious software on a banking server to capture unencrypted PINs as they passed through.

What that means for consumers is that their PINs were stolen from machines that showed no signs of tampering they could detect. In previous PIN thefts, thieves generally took steps that might draw notice -- sending "phishing" e-mails, for example, or installing false-front keypads or even tiny cameras on ATMs.

Getting the PINs is a key step for identity thieves. It lets criminals encode stolen account information onto blank ATM cards and withdraw piles of cash from compromised accounts.

Don Jackson, director of threat intelligence for SecureWorks Inc., said he has seen an "alarming" spike in the number of attacks on back-end computers for ATM networks over the past year.

"This was fairly large, but I don't think it's anything out of the ordinary -- these kinds of scams go on every day," Jackson said. "What makes this case unique is the sheer luck of happening upon these guys and catching them red-handed. But there are a whole lot of other ATM and PIN compromises going on that aren't reported."

The alleged plot is outlined in court papers supporting the prosecution of three people _ Yuriy Rakushchynets, Ivan Biltse and Angelina Kitaeva. They were indicted in March on two counts each of conspiracy and fraud. Prosecutors say their activities generated at least $2 million in illegal profits.

Defense lawyers for all three people did not return calls for comment, and it was not clear where they had been living. The main defendant, Rakushchynets, was described as having Michigan and Florida's driver licenses in a February FBI affidavit for an arrest warrant.

Citibank, part of Citigroup Inc., has declined to comment on the technique or how many customers' accounts were compromised. It said it notified affected customers and issued them new debit cards.

"We want our customers to know that, consistent with legal requirements, we do not hold them responsible for fraudulent activity in their accounts," the bank said in a statement.

Cardtronics said it is cooperating with authorities but otherwise declined to comment. Fiserv spokeswoman Melanie Tolley said the intrusion didn't happen on Fiserv's servers.

"Fiserv," she said, "is confident in the integrity and security of our system."