Police in at least two cities advise consumers not to use their debit
card at a gas pump because there’s no way to be sure it hasn’t been
tampered with.
By Herb Weisbaum
MSNBC
Becki Turner got the call from her bank’s fraud department on Labor
Day. The investigator wanted to know if she had withdrawn $500 from an
ATM in California over the holiday weekend. She hadn’t. She couldn’t.
Turner was home in Puyallup, Wash.
“I was just flabbergasted,” she says. “I had the card with me, the ATM
was in another state, and the person using the machine had to have my
security code.” Turner worried crooks had gotten into the banking
system and stolen her password.
It wasn’t anything that complicated. Puyallup police say thieves
snagged her account information — along with the debit card numbers
and PIN codes of hundreds of other people — at two gas stations in the
area.
They did it by installing their own hard-to-spot card reader, called a
skimmer, on top of the card reader built into the pump. The skimmer is
able to grab the account information from the card without interfering
with the legitimate payment transaction.
The crooks used the stolen data to create (or clone) fake debit cards
that were used at ATMs in Washington State over the Fourth of July
weekend and in Northern California on Labor Day weekend. The bad guys
like three-day holidays because it gives them more time to use the
cards before the unauthorized withdrawals are spotted.
“We are looking at a sophisticated, very well-organized group of
individuals,” says Detective Jason Visnaw with the Puyallup Police
Department. When all the victims from these two incidents are
identified, the total loss could reach half a million dollars.
Why steal debit card numbers? “With a credit card you have to go and
buy merchandise and then you have to fence it or pawn it,” Det. Visnaw
explains. “With a debit card, you’re getting cash money.”
This is not an isolated case. Gas pumps are being compromised in
cities across the country. “We don’t view it as an epidemic, but there
are cases open in at least a half dozen states right now,” says Ed
Donovan, spokesman for the U.S. Secret Service. These investigations
are underway in California, Nevada, Pennsylvania, Delaware and
Washington.
Donovan tells me the Secret Service believes some of these crimes are
inside jobs, involving someone at the service station.
Gas pumps are just the latest target
Skimming credit cards and debit cards is not new. Portable card
readers make it possible for anyone to copy the information stored on
a card’s magnetic stripe. This information is not encrypted so it’s
easy to steal.
“You just run it through the skimmer and it has all the information
right there in plain text,” says former White House cyber security
advisor Howard Schmidt. “It’s very easy to imprint that data on
another magnetic strip and use it somewhere else.”
The first skimming cases were reported at restaurants and stores where
dishonest employees ran cards through their reader before ringing up
the sale. As technology improved, the bad guys developed skimmers for
ATMs. Now they’ve added gas pumps.
The skimmers are designed to slip over the real card reader. They can
be hard to spot. And quite frankly, most of us would never look for
something like this anyway. We want to pay and go.
So how do they get your PIN number? They can hide a little camera in
the skimmer or on the pump. It shows your fingers as you type in the
number.
There are also fake keypads that slip over the real keypad that can
transmit the PIN code as you enter it.
In Las Vegas, police have discovered even more sophisticated
technology – wireless transmitters installed inside the pump. “They
can actually sit in the parking lot with a laptop and get real-time
information as victims use their card,” explains Lt. Robert Sebby of
the Las Vegas Metropolitan Police Department. Because there’s nothing
on the outside of the pump, there’s no way you can tell the pump is
compromised.
Not a safe way to pay
Nancy and Jim Tew no longer use their debit cards to pay at the pump —
and for good reason. They both had their debit card numbers stolen at
one of those gas stations in Puyallup, Wash.
Nancy Tew found out about the theft when her card was rejected at the
grocery store. “To my astonishment, I had no money in the bank,” she
said.
The thieves used her account number at ATMs in Hollywood, Calif., to
steal $600. They got $900 from her husband’s checking account. She
tells me it was “totally bizarre and really scary” to be targeted like
that and not even know it.
The Tews now pay for their gas — with cash or debit card — at the
register. That may sound paranoid, but other victims of this skimming
attack tell me they now do the same thing.
Police in Puyallup and Las Vegas now advise residents not to use their
debit card at a gas pump because there’s no way to be sure it hasn’t
been tampered with.
That’s smart advice and here’s why. Debit cards do not offer the same
fraud protection as credit cards. If crook armed with a skimmer snags
your credit card number and uses it to buy things, you can dispute the
charges with the credit card company. You won’t owe a thing while they
investigate.
If the crook grabs your debit card number, he can go to a cash machine
and pull money out of your checking account. It could take days for
the bank to investigate and put that money back into your account.
During that time checks could bounce or you might not be able to pay
your bills. That’s why the only way I pay at the pump is with a credit
card.
Cyber Security Tips N Tricks describes various tips and tricks about cyber security, safe surfing, ethical hacking, network security, Internet, news related to software, hacking, security breaches, vulnerabilities, phishing, google, yahoo, CERT, US CERT, security agencies, etc.
Showing posts with label wireless. Show all posts
Showing posts with label wireless. Show all posts
Tuesday, November 4, 2008
Beware of debit card skimmers
Labels:
atm,
bank fraud,
cyber attack,
debit card,
frauds,
hijack,
police,
skimmers,
US,
wireless
Tuesday, July 24, 2007
iPhone Hacked Successfully - Security Firm Says
iPhone Hacked Successfully - Security Firm Says
A vulnarabilty has found in the Apple Inc.'s iPhone handset that can help an attacker to gain access to the private data stored on it. This flaw has found by a team of security expert of Independent Security Evaluators (ISE). Hackers could gain access to the iPhone through a wireless access point or through a website controlled by the attacker. This was the first major security incident reported.
Numerous hackers have been working to gain access to the iPhone in order to activate certain features or to allow it to be used on cellular networks. However, this is the first major exploitation of an iPhone security flaw.
The expolit is delivered via a malicious web page opened in the Safari browser on the iPhone, ISE said on its Website. There are several methods that an attacker utilize to get a victim to open such a webpage.
1. An attacker controlled wireless access point:
The iPhone connects to wireless Internet access networks, such as Wi-Fi, an attacker could create a network with the same name and encryption method as one the handset already uses. The attacker could then substitute a Web page with exploit code to gain access to the phone.
2. A misconfigured forum website:
A link planted on an unedited or unmoderated online forum, an attacker could cause the exploit to run in any iPhone browser that viewed the thread.
3. A link delivered via e-mail or SMS:
A link sent by SMS or e-mail to use make use of the flaw and gain access to the handset.
The ISE said that when the iPhone's Safari browser opens a malicious Web page, malicious code can be run on the phone via the flaw, allowing the attacker to read the iPhone's SMS log, address book, call history, and voicemail information, which are also then sent to the attacker. It could send the user's mail passwords to the attacker, send text messages that sign the user up for pay services, or record audio that could be relayed to the attacker.
Source: nytimes
A vulnarabilty has found in the Apple Inc.'s iPhone handset that can help an attacker to gain access to the private data stored on it. This flaw has found by a team of security expert of Independent Security Evaluators (ISE). Hackers could gain access to the iPhone through a wireless access point or through a website controlled by the attacker. This was the first major security incident reported.
Numerous hackers have been working to gain access to the iPhone in order to activate certain features or to allow it to be used on cellular networks. However, this is the first major exploitation of an iPhone security flaw.
The expolit is delivered via a malicious web page opened in the Safari browser on the iPhone, ISE said on its Website. There are several methods that an attacker utilize to get a victim to open such a webpage.
1. An attacker controlled wireless access point:
The iPhone connects to wireless Internet access networks, such as Wi-Fi, an attacker could create a network with the same name and encryption method as one the handset already uses. The attacker could then substitute a Web page with exploit code to gain access to the phone.
2. A misconfigured forum website:
A link planted on an unedited or unmoderated online forum, an attacker could cause the exploit to run in any iPhone browser that viewed the thread.
3. A link delivered via e-mail or SMS:
A link sent by SMS or e-mail to use make use of the flaw and gain access to the handset.
The ISE said that when the iPhone's Safari browser opens a malicious Web page, malicious code can be run on the phone via the flaw, allowing the attacker to read the iPhone's SMS log, address book, call history, and voicemail information, which are also then sent to the attacker. It could send the user's mail passwords to the attacker, send text messages that sign the user up for pay services, or record audio that could be relayed to the attacker.
Source: nytimes
iPhone Hacked Successfully - Security Firm Says
iPhone Hacked Successfully - Security Firm Says
A vulnarabilty has found in the Apple Inc.'s iPhone handset that can help an attacker to gain access to the private data stored on it. This flaw has found by a team of security expert of Independent Security Evaluators (ISE). Hackers could gain access to the iPhone through a wireless access point or through a website controlled by the attacker. This was the first major security incident reported.
Numerous hackers have been working to gain access to the iPhone in order to activate certain features or to allow it to be used on cellular networks other than AT&T Inc.'s. However, this is the first major exploitation of an iPhone security flaw.
The expolit is delivered via a malicious web page opened in the Safari browser on the iPhone, ISE said on its Website. There are several methods that an attacker utilize to get a victim to open such a webpage.
1. An attacker controlled wireless access point:
The iPhone connects to wireless Internet access networks, such as Wi-Fi, an attacker could create a network with the same name and encryption method as one the handset already uses. The attacker could then substitute a Web page with exploit code to gain access to the phone.
2. A misconfigured forum website:
A link planted on an unedited or unmoderated online forum, an attacker could cause the exploit to run in any iPhone browser that viewed the thread.
3. A link delivered via e-mail or SMS:
A link sent by SMS or e-mail to use make use of the flaw and gain access to the handset.
The ISE said that when the iPhone's Safari browser opens a malicious Web page, malicious code can be run on the phone via the flaw, allowing the attacker to read the iPhone's SMS log, address book, call history, and voicemail information, which are also then sent to the attacker. It could send the user's mail passwords to the attacker, send text messages that sign the user up for pay services, or record audio that could be relayed to the attacker.
Source: nytimes
A vulnarabilty has found in the Apple Inc.'s iPhone handset that can help an attacker to gain access to the private data stored on it. This flaw has found by a team of security expert of Independent Security Evaluators (ISE). Hackers could gain access to the iPhone through a wireless access point or through a website controlled by the attacker. This was the first major security incident reported.
Numerous hackers have been working to gain access to the iPhone in order to activate certain features or to allow it to be used on cellular networks other than AT&T Inc.'s. However, this is the first major exploitation of an iPhone security flaw.
The expolit is delivered via a malicious web page opened in the Safari browser on the iPhone, ISE said on its Website. There are several methods that an attacker utilize to get a victim to open such a webpage.
1. An attacker controlled wireless access point:
The iPhone connects to wireless Internet access networks, such as Wi-Fi, an attacker could create a network with the same name and encryption method as one the handset already uses. The attacker could then substitute a Web page with exploit code to gain access to the phone.
2. A misconfigured forum website:
A link planted on an unedited or unmoderated online forum, an attacker could cause the exploit to run in any iPhone browser that viewed the thread.
3. A link delivered via e-mail or SMS:
A link sent by SMS or e-mail to use make use of the flaw and gain access to the handset.
The ISE said that when the iPhone's Safari browser opens a malicious Web page, malicious code can be run on the phone via the flaw, allowing the attacker to read the iPhone's SMS log, address book, call history, and voicemail information, which are also then sent to the attacker. It could send the user's mail passwords to the attacker, send text messages that sign the user up for pay services, or record audio that could be relayed to the attacker.
Source: nytimes
Thursday, June 14, 2007
Michigan Man Fined for Using Coffee Shop's Wi-Fi Network
A Michigan man has been fined $400 and given 40 hours of community service for accessing an open wireless Internet connection outside a coffee shop. Under a little known state law against computer hackers, Sam Peterson II, of Cedar Springs, Mich., faced a felony charge after cops found him on March 27 sitting in front of the Re-Union street Café in Sparta, Mich., surfing the Web from his brand-new laptop. Last week, Peterson chose to pay the fine instead as part of a jail-diversion program.
Someone from a nearby barbershop had called cops after seeing Peterson’s car pull up every day and sit in front of the coffee shop without anybody getting out.
“I just curiously asked him, ‘Where are you getting the Internet connection?’, you know,” Sparta Police Chief Andrew Milanowski said. “And he said, ‘From the café.’”
Milanowski ruled out Peterson as a possible stalker of the attractive local hairdresser, but still felt that a law might have been broken.
“We came back and we looked up the laws and we figured if we found one and thought, ‘Well, let’s run it by the prosecutor’s office and see what they want to do,’” Milanowski said.
A few weeks later Peterson said he received a letter from the Kent County prosecutor’s office saying that he faced a felony charge of fraudulent access to computer networks and that a request had been made for an arrest warrant.
Source: FoxNews
Skype is great!
Labels:
computer misuse. michigan,
hacking,
internet,
law,
legal,
legal issues,
wifi,
wifi jacking,
wireless,
wireless jacking,
wirless
Subscribe to:
Posts (Atom)