The rest of it seems fairly accurate based on jstash/unicc/etc.
The rest of it seems fairly accurate based on jstash/unicc/etc.
Some time ago I accidentally stumbled upon how some organized crime ring determined which credit cards worked. Someone in my party asked the Uber driver one night what other gigs they do for money. He said he uses this one card to get 40% cash back. Of course I asked more questions being the only one in security at this party:
He starts talking saying he goes around to different, small, local businesses - but never visiting the same place twice - and uses this card to pay for his friends' food, splitting the bill, but keeping the cash back rewards. Sometimes the card is rejected and he has to keep trying until it works finally. The actual credit card has to frequently connect to his phone by pushing a button on the card to sync with his phone to make purchases. Of course what his phone is doing is downloading a backlog of CCN's which then is sent to the credit card to change the magnetic strip dynamically - completely unknown to him he's testing if credit card numbers are working and getting paid for it. Genius scam, but that's what this one specific crime ring has to pay in order to check the availability of stolen credit card numbers.
But if he isn't in on the scam and does pay off his card, funny enough, that must mean all of his money is going directly to the crime ring. Two birds with one stone!
Why not? ATMs work at 3AM.
> but you also have to test what credit cards work and what don't
Not really, if it’s data you skimmed yourself odds are they’ll work more than half the time.
If I was in fraud detection there would be fraud flag contagion: If 25% of them started out as blocked and you tested them all, afterwards 100% would be blocked.
I can think of ways around it myself but I don't think they're realistic for the number of times this would actually happen.
If within X minutes you see Y cards and Z of them are known to be stolen, you set the soft fraud flag on all of them. Values of X, Y and Z would be set based on historical data.
You could still test your stolen cards, of course - but 5 at a time, not 50 at a time.
Then repeat for each block of 25%.
In short, Domino’s across the US regularly receive strange orders for $2 Coke (and nothing else), which then no one ever picks up. The theory is, if a card doesn’t work, an automated script detects that as online order form switches to cash—and if it works, given the popularity of Domino’s this transaction might just slip by the cardholder’s attention.
My parents' experience suggests donating to charity probably isn't as effective any more.
Because there's almost no risk associated with it. You don't have to get a team together to hit up ATMs and extract money from those cards, which requires trust and increases complexity, you just mount a few skimmers, collect the data, remove the skimmers, and then sell it online and let someone else take the risk.
If you're the police and you have the option of spending resources on burglary or muggings (which cost an absolute fortune in police time, generally low value, but in the public's eye very important) or payment fraud, the police will put time into "in person" crime every time.
It’s really not a lot of extra risk, it’s not like the authorities could respond at the ATM in a timely manner. All the thief needs to do is cover their face.
Given that, I assume it's a very risky thing.
Doesn't seem easy at all. ATMs have cameras and are monitored for abnormal transactions (stolen cards, unusual withdrawal patterns, etc).
Unusual patterns and stolen cards are one of the primary reasons that they will rarely ever leave a team. It takes a great deal of work to gather stripe data + PIN. It's much easier to look for a website without PCI compliance. In-person carding is going by the wayside, but is much easier to accomplish if you have good data. You can buy dumps, but no one is turning over a PIN.
Cameras can’t tell you the name and address of the pixel blob that is committing the crime. Cameras as a security device are overrated. My building had countless footage of people entering the bike room or parking and stealing bicycles. Resident makes a complaint to the police, proudly says “we have cctv footage!”, police shrugs and looks at cctv footage, and nothing happens because what do you do with the video of a thief stealing your bike..?
https://www.theguardian.com/uk-news/2018/nov/11/super-recogn...
Given sufficient resolution, software, and access to data they can with some degree of accuracy.
>My building had countless footage of people entering the bike room or parking and stealing bicycles
With bicycle theft you have an individual with an incentive to recover the bike approximately equal to the retail value of the bike, and few resources at their disposal. Law enforcement is not going to pay much more than lip service to a stolen bike, because they don't have any tangible incentive to recover it, while it's probably a lot of work to even try. Depending on the building, it's possible the landlord is sufficiently incentivized to increase security to mitigate tenant complaints, but that won't extend to the search for a bike that has already been stolen.
By contrast, with bank fraud you have, for example, a $300 bn company like JPM with a strong incentive to protect their network's security and consumer trust, cameras everywhere, and good working relationships with law enforcement at many levels of government. It is much more likely to be taken seriously and acted upon, and is therefore riskier than bike theft.
Banks seems to have lots of influence and move things around. Bank thefts (where I live) net for thieves around 10-20k USD. They get lots of police action. Other thefts with even higher amounts go unnoticed.
Because now you have $25, and you don't have your face on video using a stolen debit card?
The hacker doesn't hack, but sells the information to be weaponized.
The person that weaponizes only does that to get a giant leak of data, that they sell in pieces.
The person that buys a few cards, gets 1 that works, and now we are talking about a few thousand dollars. Almost too small to care for a big investigation.
And so on and so forth.
There is rarely anyone to levy the whole force of the RICO act + CFAA + Wire Fraud + Conspiracy + Using a fake ID + etc etc
In most places finding an ATM that still uses the magnetic stripe is certainly not easy.
(Some chips aren't actually signing anything, they're just another way of reading the same info that's on the strip. It depends on the company issuing the card. This isn't covered in the video, but it's true.)
As the video shows, there are other vectors of extraction than ATMs.