Gas Theft Gangs Fuel Pump Skimming Scams
krebsonsecurity.com
krebsonsecurity.com
You can configure that amount in the online settings; change it to $0 and you'll get an alert for every transaction.
I found this useful when I was wondering about a charge that I wasn't expecting pop up. I logged into the card issuer's online portal and found that it was something I care about, but simply forgot it was pending. Though if it was a fraudulent charge, I could've just gave them a ring. It certain can help in noticing fraudulent transactions in a much shorter time frame than simply waiting for a statement.
Edit: Actually, I mis-remembered. Internet charges on the Amex do cause a notification. But not for any of the other cards.
Seeing as you have 60 days after posting to dispute a charge, immediate notification seems like overkill.
I could see the usefulness for subscriptions or to shutdown a shopping spree before it gets out of hand I guess.
It's often much more than 60 days.
We had a chargeback at work that was a couple months over a year old. That surprised me...I had thought that a year was the limit.
That's not actually the most surprising thing I learned about credit cards last year, though. We got a notification from the payment processor near the end of the year that a charge from March had been reported as a success but actually failed. By "reported as a success" I do not just mean that the API had reported success on the charge. The payment processor had also reported later that it had successfully settled. They just never actually transferred any money to us.
While talking to them on the phone the payment processor rep then told me that the same thing had happened on the charges on this customer's monthly subscription for all subsequent months.
According to the payment processor rep, the customer had told his bank that he no longer wanted our service (but neglected to tell us...). The card was still good, and so the bank still said "approved" when we would try to charge it, then would apparently later notice that the customer did not want the charge and somehow arrange to block settlement, and the payment processor apparently has no way to report this.
Notice how messed up this is: you can put through a charge on a credit card, have the issuing bank and payment processor tell you it went through, have it settle according to the payment processor, have it show up as successfully settled in all reports from the payment processor...but the money just doesn't show up.
Unless the payment processor tells you about this, the only hint you'll have that something is wrong is that there will be a discrepancy between what is supposed to have shown up in your bank account and what actually showed up, and you won't have any way to tell which charge is the one that silently failed.
Do you mind if I ask who the processor was?
I'd prefer not to name the processor since I suspect that the same problem could happen at any processor when dealing with cards from that issuing bank so I don't want to drag the processor's name through the mud.
A) you want me to type my pin into a compromised device, the pinpad at the pump
B) you expect me to remember seven pins, I carry seven credit cards (yes that's excessive) and each should have a separate pin for security, right?
Ex of a simple and secure system. cc shows transaction cost, user clicks ok on the card. Card digitally signs a transaction with time stamp, vender ID, and amount.
Want safe online transactions, add a USB dongle or Bluetooth.
But it won't save you from a compromised point-of-sale system that lies to you about how much you're paying or which commits fraudulent transactions while the card is still in the reader.
Now, if only we carried around a device that included a display and some sort of input mechanism, plus a near-distance communication chip...
(Ok, if the device is a general computing device, a special secure operation mode might be needed for this sort of use case, one which can't be subverted by normally installed software, but still...)
Now people will complain that "the app doesn't run on their rooted, bootloader unlocked, jailbroken phones"
I mean, you can mod the brakes on your car if you really want to, at your own risk. What is a bit strange is when your media player can affect your brakes without you even noticing. Same principle here, less lives on the line.
If you're not going to do chip and PIN (and you should), why not just chip and nothing?
Thankfully we've now got chip & pin, completely removing the need for minimum wage retail staff to verify ownership of credit cards.
NPR's Planet Money recently did a story on the signature in CC payments. The answer seems to be "not really".
"Today on the show: the signature. It's supposed to say, "This is me." But where did the idea come from? And why are we still using it? We consult a rabbi, a lawyer and a credit card executive."
http://www.npr.org/sections/money/2014/08/29/344034815/episo...
(It wasn't NFC exactly, but similar technology)
In this case, when all five banks decided to go to pin-enabled credit cards, they just did it. Retailers were given a certain amount of time to switch over, “or else.” There are few alternatives, so the entire country moved forward.
Whereas, south of the 49th parallel, there is all kinds of competition for credit cards and for merchant services, so if a few banks don’t feel like sending out cards with chips an PINs, they don’t. And if a few retailers don’t want to go to the expense of upgrading their systems, they don’t have to.
On the flip side... There is nearly zero Apple Pay up here.
Some one has demoed a proof of concept system that you could hide in a back pack and walk through a crowded train/tube station and harvest small sums from hundreds of people.
Why do people sign up for text alerts and notifications on smartphone apps for certain purchase amounts? You're just doing the credit card company's job for them. At that point, what's the point? You're probably getting a new card number in a few days anyway.
Not trying to be flippant, I'm genuinely curious why people obsess over some of this as a consequence-free user.
In what way? You stated in your first paragraph that it's your responsibility to report fraud.
Regardless, it's not about being responsible for the charges, it's about not having to read a full credit card statement every month, looking for potentially fraudulent charges in a list of transactions made days or weeks prior. With a notification, I'm not looking at my credit card bill trying to figure out what the $45 charge to "AAZZYBD Ind. Co. Ltd." was (could be an Olive Garden, could be a gas station, could be a deep web retail site).
Going through notifications after each purchase, or looking at a monthly bill, you're doing the same thing but in different time periods. We're all on the brink of app notification overload, I don't need one for each purchase I or my wife makes.
This way I have to only worry about the ATM having a skimmer attached to it. Not every random semi-seedy place that I buy food or gas from.
Sure I know cash can be a pain. But CC fraud and skimmers are making using a CC a pain as well.
But what about outside the US?
Also this requires someone to religiously check the credit card statements, there is a time limit in which to report fraudulent transactions. (FYI: this is why I still get paper statements -- to remind myself to check)
Because your card gets cancelled and you have to wait for a new one to come in the mail
Oh but you're not home and are travelling instead. Good luck paying for your hotel then
What a well thought-out system!
This seems like the easiest way to tackle this problem (aside from chip cards). I doubt it would take much pressure on these guys to get the market for this to dry up, or at least considerably reduce the profitability. I'd guess the gas station owners have a lot more to lose than the thieves actually stealing gas.
People steal the brass end caps off hydrants. Dozens of them. Sell them to scrap metal places.
That conversation, I'm certain, doesn't go like "Oh, hey, I'm Bob from the Fire Department, getting rid of old hydrant caps" "Oh, sure! Sounds legit, Bob, let me give you some cash!"
This would open up innovation and I'm sure this would lead to interesting solutions for combatting the fraud.
For example, they would make sure to go to the gas stations that you frequent. Or to the electronics store that you made a purchase at recently.
I worked at Citibank. They are barely competent. Don't ask for more access, they will probably screw it up.
http://europa.eu/rapid/press-release_MEMO-15-5793_en.htm?loc...
https://purpledelivery.com/app (LA, OC, & San Diego)
Looks cool, though, would be interested when you come to San Francisco.
This should be handled by the CC industry. US pumps should have chips like they do in most every other developed nation. It's an arms race, but prevention is easier than investigation.
And do not blame "the attendants". I worked as a light mechanic at one of the last truly full service stations. The pump/retail guys are payed minimum wage on flexible shifts to do a job that is actually rather dangerous. Only one of possibly a hundred attendants may know anything about the skimmer install. The guys who own/run the stations should also not be above suspicion. My bosses were some rather shady characters.
"Financial Crimes, covering missions such as prevention and investigation of counterfeit U.S. currency, U.S. treasury securities, and investigation of major fraud."
https://en.m.wikipedia.org/wiki/United_States_Secret_Service
It is almost always better/cheaper to prevent a crime from happening by removing the opportunity. Without bringing in spreadsheets and US federal budget reports, having the CC industry deploy a technological solution is cheaper than investigating, trying, arresting and housing these criminals. Gas pumps are expensive units, require regular service, and each move thousands of dollars worth of gas every day. A few bucks for the chip reader is no great burden.
It's a risk-cost tradeoff. Many people desperate enough to work in these areas are happy they actually got even a shit job and don't intentionally defraud their employer (and losses due to customer theft are priced in, anyways). The bet is on those who are crazy/desperate enough to actually exploit the weaknesses in the system to commit bigger fraud - and how much damage is to be expected.
Now, take the expected damage and contrast it with paying your employees more, and I bet that it's cheaper risking one or two 10K thefts a year than paying all employees more which can be, even if you're only running a 10-employee shop and raise salaries by 2-3K/yr, the cheaper option.
Well, in the end customers are paying with the (exorbitantly high) CC fees. It's all priced in.
Although, I'm not sure what's worse, the penalties or the interest if you don't fully pay your balance every month.
I'm confused: Are you talking about chips in the pumps - or the cards? The article seems to show a deep integration into the pumps to steal not only the magstripe data, but also the PIN. So I guess they already target chip & pin systems?
Plus, depending on the architecture of these systems you can 'degrade' a transaction from 'needs pin' to 'pin not required' (we had a couple of related downgrade articles here on HN and the 32C3 had - specific to Germany, but acc. to the authors probably somewhat applicable elsewhere - a talk about direct attacks against payment terminals to do the same thing).
If they did, the headlines would suddenly be "Credit card companies forcing mom and pop shops to spend thousands on new equipment"
---- On Oct. 1, 2015, Visa and MasterCard put in force new rules that can penalize merchants who do not yet have chip-enabled terminals. Under the new rules, merchants that don’t have the technology to accept chip cards will assume full liability for the cost of fraud from purchases in which the customer presented a chip-enabled card.
But those rules don’t apply to fuel stations in the United States until October 2017, and a great many stations won’t meet that deadline, said Verifone’s Turner. ----
According to "Yearbook 2005: British Retail Consortium" [1], by the time of the liability shift (1 January 2005) "retailers accounting for 75% of transactions" had a chip+PIN terminal, with the remainder "well on the way". It goes on to explain that small businesses including petrol stations were consulted as the change was planned, there was no relaxed deadline for them. (If my memory is correct, petrol station pumps were among the first to switch, as they had the highest level of fraud — relatively high-value transactions with no supervision.)
[1] https://books.google.dk/books?id=csUYwwVZ2AUC&pg=PT207&dq=ch...
The article involves a scam that is slightly larger potatoes and was newer than I expected. I was under the impression that skimmer problem had been largely neutralized (not sure where I got the idea, maybe something to do with new chip card rollout). Guess not.
http://www.pressdemocrat.com/news/3869514-181/low-tech-thiev...
Or something. I'm having trouble understanding this scam as well.
This doesn't apply to gas stations until October 2017. Assuming that the card industry doesn't blink, the problem should solve itself fairly quickly given that margins on gas stations are razor thin so if they have to eat the fraud then they will be lining up to install the new readers.
personally I use cash everywhere I can, it's not just tinfoil-hat thinking, it's far less hassle
for everywhere else, just use low-balance gift cards
I just love it, nobody can state anything objectively and with detachment anymore, everything is politically overloaded, even stuff that could be even as consensual as thievery.
These things are literal rolling bombs. Diesel is not as critical (it doesn't emit explosive vapours and you need higher temperatures to get it to burn, and unless you vaporize it it will just burn and not explode), but take one of these trucks with 1 ton of petrol in plastic tanks and you got yourself a pretty nice fire/explosion hazard. Not to mention that ordinary plastic gets attacked by the petrol and thus will be weaker than the same tank filled with water.
All this needs to go off is a single drunk driver slamming into such a truck. To those who still think "ah that's harmless, just a fire", go visit your local fire department at an exercise session and watch how powerful just a liter of burning petrol is, then scale this up to a 1-ton-payload truck spewing the stuff everywhere.
There's a reason why ordinary fuel trucks are heavily regulated (e.g. in Germany, they're not allowed on roads in environmentally protected zones, must carry a number of fire extinguishers, have a speed limit of 60 km/h on country roads and 80 km/h on Autobahns, the drivers must be specially licensed).
Diesel might seem better, but there are issues. Gas will burn/evaporate away and be gone. Diesel gets into soil and lingers, creating more environmental damage than if gas was left to burn away. The driver is safer hauling diesel, but the environment is safer if he hauls gas. This conflict is more dramatic with propane trucks (bigger fire risk, but no real chance of soil damage).
All the more reason to be fucking afraid. One bad weld and the entire tank ruptures when slammed into (or it might just fail from ordinary vibration!). Or it leaks either gas or a sloppy weld on the top side vents fumes - the OP actually mentions a driver lighting a cigarette, causing his truck to explode.
Welding together a truck might cause it to fall apart. Welding a tank might cause a disaster.
And frankly, maybe I would do it too in some circumstances, it's DIY, the tank has exactly the size and shape you need and you live only once, so I might rationalize the risk (on the other hand, I don't think I would ever do a custom roto-casting or blow-molding of a significant size, that looks like a pain in the butt and a lot of tooling for a one-off).
edit: of course, you'll have the prepper, the boat enthusiast, the car or truck modder, the american wild lover, and a bunch of other people carrying sketchy home made gas tanks everywhere around you in the land of freedom.
(Also, I'm pretty sure you're wrong about every single accident leading to fire. Fender-benders and low-speed collisions do happen.)
-These trucks have no HAZMAT signs to alert first responders to the dangers within.
-There is no separation between driver and cargo, so things like smoking or even electrical sparks could ignite the gasoline.
-These bladders don't appear to be commercially engineered or fit for this purpose. They could easily leak.
-The trucks pictured are running well over their rated payload capacity and are 10+ years old. 500 gallons of gasoline weighs 3125 lbs and even the large Excursion shown is only rated for 1500-2000 including driver and legitimate fuel.
-The drivers are incentivized to run away from police at the scene of an accident and their insurance won't cover criminal activity. If a commercial fuel truck catches fire and someone gets injured due to burns, they'd have to pay.
-The drivers aren't properly trained for handling hazardous materials. They could do things like stall on railroad tracks and kill hundreds of people.
To me, the risk seems much higher than a hobbyist with a custom hot rod or a legitimate tanker truck.
Steel tanker trucks must be able to withstand more of an impact without issue than a plastic bladder in a van, no?
Normal trucks are not stupid, it's just that past a certain size, only steel can hold the static force of the liquid. There are contradictory factors, you want the cargo to be held firmly in place when you brake, but you want the tank to be accepting a lot of deformation before breaking. I'm not sure, but a secondary concern might be contamination, I'm not sure you can switch liquids in a plastic tank, while you can clean a steel tank.