How Carders Can Use EBay as a Virtual ATM
krebsonsecurity.com
krebsonsecurity.com
In the same way that cartels use hundreds of drug mules to smuggle drugs across the border knowing that a certain percentage will be caught and a certain percentage will succeed, carders are now using this same pattern. Instead of placing a small number of orders for a high value, place a large number of orders for a medium-to-high value under the assumption that some will go through.
Looking at the e-commerce store mentioned in Brian's article, it seems they're simply new to the scene and haven't understood that credit card fraud using physical items follows 3 patterns:
1. Billing and shipping address are different.
2. IP address is geographically far from the billing address OR its a server/EC2/VPN. Note: Yes, carders sometimes use proxies near the billing address BUT ask yourself, if they're shipping it to a separate address with (presumably not to attract suspicion) the same "ship to" name as the "bill to" name, why would they ship it elsewhere? I have seen carders that will use the same last name but with a different name, making it appear that its a relative or family member, but those are usually few and far between and still flagged for other reasons.
3. Credit card number was pasted instead of typed.
This wouldn't probably work. You have to consider that some browsers (eg. Chrome) save the CC data, so you don't have to type them. This validation step would block legit customers from buying what they want.
Also, bots can run on real browsers simulating real humans using infected PCs as proxy so that their IP addresses result on the same country/state of the real customer.
Is this really a signal? I've never had issues with this.
I had no idea people are working so hard to buy stuff with fake or stolen credit card information. Bots running on AWS to sell stuff on eBay, then actually purchase the sold item and have it sent to the buyer. Wow
Given all the call centers and operations in India and the Philippines, for example, these low-wage countries may have a good number of people who understand how eBay and PayPal systems work. They certainly have a number of tech savvy and multi lingual folks.
If these really are Indian based, I'd argue their modern robin hood efforts aren't a good idea. However I know next to nothing about Indian culture, and we don't really know where the origin of the scam is coming from. It could be US based.
[rant]
In general, I'm unimpressed with the ability of the US government to identify major online scamming patterns and execute effectively deterring consequences for the perpetrators, as well as enact legislation that is not overreaching.
I recall one I got hit by a buyer's club called Reservation Rewards / Web Loyalty in 2007. They started in 2000. They still exist and are still scamming people under the name Affinion, Trilegiant and a host of other buyer's club names that they come up with.
In 2007, I had entered my email address twice to receive some coupon after registering for a road race on active.com. Unbeknownst to me, this legally authorized them to share my credit card with another company and start billing me $10 monthly. Apparently at that time, entering your email into two different text boxes constituted a legal signature. I didn't read the fine print because it just looked like a coupon that would be emailed to me. It didn't look like I was buying anything. I never thought my CC # could be transferred like that and have me charged by a different company. I think the partnering company (active.com, fandango.com, and others) gets a kickback from RR's "coupon" scam which is a modern discount buyer's club.
Anyway, I didn't notice the recurring charges for a few months. Once I did I found this company had been scamming people for years, since 2000. I called to get a refund and got it back in full. They put up some resistance, but having read other peoples' experiences, I knew what they would say and what I should say back. I wrote a few lengthy comments online, considered that my contribution and moved on.
There was a TV report done on them in 2009, in which their CEO stated they were following all laws in all states [1]
Web Loyalty was subsequently involved in a class action lawsuit, in which they settled [2]
According to a review on Glassdoor from a former employee, the company has since been sold to another one called Affinion [3]
There are several revealing Glassdoor reviews from current Affinion employees, this one is worth sharing [4]
In October 2013, Affinion settled with 46 state attorneys general to refund $19 million to tricked consumers. [5]
There are many complaints about Affinion on BBB.org, some of which look just like the old ones about Reservation Rewards / Web Loyalty. That is, charges for services for which people never signed up [6]
There are also some recent complaints about "Web Loyalty" here on BBB although they really fall under Affinion now. [7]
I recall reading one comment where a person was only billed once every six or 12 months, rather than monthly, so they nearly missed it.
This company has been operation for 15 years and is clearly still scammy. I'm sure lawyers would look at this and tell you it happens all the time. It's their job to see this.
To me, this is unacceptable. When you steal cash from a store you go to jail. When you scam people out of money over the internet, you get fined some amount less than your profit, make some minimal adjustment to your scamming service, perhaps sell the business to another one, get a new name and then resume as usual with a small hit to profit.
Our society does not benefit from the little money coming back via these fines.
When is our government going to learn that fines are not a proper deterrent for super scale larceny?
[1] https://www.youtube.com/watch?v=v0RzjkOirHg
[2] http://www.xconomy.com/boston/2009/08/27/webloyalty-customer...
> "A sinking ship with part of the hull still miraculously above water. Affinion is a "Business Parody" at best."
> Pros
> I cannot, in all honesty, find one single benefit of choosing Affinion as an employer as opposed to the next company. Like quicksand, every reason for working there gets sucked into an abyss.
> Cons
> The only benefit of ever working at Affinion would be the lesson one could learn about how unethical companies with a sketchy business model are able to survive this long. At best, it is a sinking ship on its last leg of survival.
> Advice to Management
> Those in "upper management" play their "oblivious" roles to perfection. The fact is, the emperor has no clothes on...and yet every one of them can describe the non-existent clothes to the last thread.
[5] http://www.cleveland.com/consumeraffairs/index.ssf/2013/10/a...
[6] http://www.bbb.org/connecticut/business-reviews/buying-clubs...
[7] http://www.bbb.org/connecticut/business-reviews/buying-clubs...
[/rant]
And please don't blame only third world citizens - most of the time they're just grunts, the masterminds are usually in the countries where cards are actually stolen from (i.e. first world, rich, etc.)
Sorry, I don't buy it. We don't know exactly the details of how these scams are happening or who is conscious of what they're doing. However, whoever does control the details of setting up on AWS can certainly make a living wage elsewhere.
Stealing is not acceptable within any society. We are all human beings, we share this earth, let's share not steal.
Now couple it with the gang aspect.
I don't know what you mean by gang aspect. Yes organized crime exists and forces people to participate. Are you saying there's a high likelihood that the people who set up these scams are being forced to do it by a gang? I don't know anything about the likelihood of that. As far as I know, all participants in tech criminal rings are willing. If people are being forced to join against their will, someone should shed light on that.
> If you want to solve most crime issues in a real way, stop it from being the only choice many people have to "get ahead" or even survive
Globalization provides more international tech jobs daily. Governments and businesses are opening schools across the world to teach towards these jobs and try to keep pace with the growing population. Internet access for self-training is accessible in many third world countries. This infrastructure doesn't build itself. Most people will contribute towards making it better.
> Crime is unquestionably coorlated with poverty, you can't just dismiss that with banal moralizations of how BAD these people are
I'm not. We don't know the details here but we can make an educated guess. We know that someone in this operation knows how to work with AWS. We also know that there are tech jobs in every country. We don't know exactly what the job opportunities are like in the area of the actual thief who knows what he's doing, but we can imagine there is a tech job they could land.
Let us not call theft acceptable when there is evidence that the thief seems to have the skill to get a decent job.
From the top to the bottom, everybody steals, but only the pawns take the fall when the time comes. Look for the head of a problem (and cut it off), not it's tail...
Yes of course people steal, and it is forgivable. Nonetheless, it's not legal anywhere. Most of us do not knowingly make an entire living out of stealing while we could be pursuing legitimate job opportunities elsewhere. Everyone makes their own choices.
> From the top to the bottom, everybody steals
Everyone does not steal for a living. Most people contribute towards making happier communities. Are people perfect? No. If I see one criminal get away with a crime in my community, does that justify my criminal behavior? Do two wrongs make a right?
> only the pawns take the fall when the time comes. Look for the head of a problem (and cut it off), not it's tail...
That is case by case and you cannot say it is always the tail. CEOs and presidents alike have been fired, jailed or forced from office.
2-factor authentication is now a well known process. How come you can still order things with a card number and nothing else whatsoever?
Well, here are my 2 guess, not exclusive:
- fraud prevention is actually a lucrative business, and having better security would destroy a cash cow
- the added security is deemed too hard for a large part of the population, and would raise support cost too much
It raises the question, not begs it. To beg the question is to engage in circular reasoning.
> - the added security is deemed too hard for a large part of the population, and would raise support cost too much
I think that this is a big part of it.
There's also the fact that really, cryptographically-secure cards cost more, and that someone would have to pay for the readers themselves, and (I believe) there's no infrastructure in place to prevent evil-retailer.invalid from charging one's card for more than one actually wanted to authorise.
With the rise of cell phones, I think that there's a real opportunity to build cryptographically-secure payment and identity protocols. A smartphone is, after all, a general-purpose computer that fits in one's pocket. The tough part isn't implementing the protocols; it's defining them, and making them user-friendly.
"Older people"
When I think of how difficult it was to teach my grandparents how to use the Picture in Picture functionality of their projection TV, when they were in their 50s... It makes me very afraid of how well people of their generation would handle two factor authentication on their credit cards, now that they're in their 70s and 80s.
Visa 3d secure is popular now though.
It's nearly impossible for normal users to verify that they're sending their password to their bank, and not to the merchant.
Training users to send merchants sensitive bank passwords is a step backwards.
I think the reset process requires postcode & DOB (in the UK anyway) which would high a good probability of being available in the data-dump type scenario.
in comparison, all online banking transactions go through a challenge-response process with an separated card reader and my debit card.
Obviously it doesn't solve the issue of someone using my card on a foreign website.
No, it raises the question.
Nowadays it is very easy to register an alternative address with your CC that the merchant can verify so besides that bit of friction I don't see the merchant losing much business.
Given that Amazon and Ebay accept my card, if another retailer rejects it they'd need a pretty compelling offer for me to take a day off work to receive their delivery.
This could cut fraud drastically - that is if merchant has any clues about security.
"Your card just been used to buy X for $N at Y. Click here if you think it's not authorized".
Or more proactive: "... click here to confirm" - this way IP of email click could be used additionally to detect possible phishing victim.
This could cut the fraud drastically and allows to catch a few fraudsters while still "warm".
Way cheaper, simpler and more efficient then struggling with EMV.
Additionally, I lost the respect for him when he questioned the validity of Ashley Madison site data breach, disregarding confirmation of many other sources but solely based on the interview he had with Raja Bhatia, ex-CTO of Avid Life Media, who was proven to be clueless about security in retrospect. Brian Krebs later did retract his original reporting with an update shortly after overwhelming evidences proved he was wrong.[1]
Basically, he's neither a security research nor a good investigative journalist IMMO.
[0]: http://krebsonsecurity.com/cpm/
[1]: http://krebsonsecurity.com/2015/08/was-the-ashley-madison-da...
"i fail to see how this stop hackers, who use stolen ebay/paypal accounts."
It won't. But this article says nothing about stolen Ebay/Paypal accounts, that's completely different problem.
"A buyer's Confirmed Address is checked against the credit card billing address maintained by his or her credit card company, or is verified by PayPal"
So if you do change shipping address to match the card holder's, item will be shipped to the legitimate card holder and the whole scheme becomes pointless -- you just bought unwanted item for somebody using their own money and probably get disputed by the buyer, whose order didn't arrive. A more simple way to achieve the same goal would be "take money and disappear", but it's not quite the same as "ATM on Ebay".
ebay do not let you sell or buy without a paypal account. which only allows credit card from a single country.
so why can't the police link the two things easily? seems to me people are either hacking paypal to somehow get the money out or paypal is going out of the way to make it disappear.
either that or using stolen credit cards for online purchase is completely safe.