PSN Users Reporting Hundreds of Dollars Stolen From Them
vgn365.com
vgn365.com
Certainly possible that it's purely coincidental, but seems unlikely.
Come to think of it, though, what is the sensible way to use some vast number of credit card numbers to enrich yourself? I assume small-time credit card thieves can get away with it because they're sufficiently small-time to escape an in-depth investigation, but is there any way to untraceably pay yourself?
I'd bet that it's not the person who stole the 75e6 credit cards that is buying gas, someone bought that number for $5 on some shady site.
Selling them. At 5$ a piece they will make 375 million dollars. People who buy them are then most likely to use them for this kind of purchase, where it might be hard to get caught.
You're assuming that the police care enough to actually investigate the crime. From my experience in web-based sales, the authorities don't seem terribly interested in pursuing cases of credit card fraud.
(If this weren't HN, I'd add something sarcastic about them being too busy hunting down speeders and feeling up travelers)
OTOH, a good security mindset should probably assume that the attackers will use the ill-gotten data in some malevolent way, not just for lulz.
Given the following:
"The Consumer Sentinel Network (CSN) is a secure online database of millions of consumer complaints available only to law enforcement. In addition to storing complaints to the FTC, the CSN also includes complaints filed with the Internet Crime Complaint Center, Better Business Bureaus, Canada’s Phone Busters, the U.S. Postal Inspection Service, the Identity Theft Assistance Center, and the National Fraud Information Center, among others."
The CSN received 1.2 million complaints in 2008, 62400 of which were specifically credit card fraud.
This means that of the approximately 170 million+ credit card owners in the US, roughly 0.035% of them reported credit card fraud in such a way that CSN saw it. There are likely many more cases that only get reported directly to banks without reaching CSN.
0.035% of 70 million+ users? 24500 people. All of which, due to PSN being an online service, have internet connectivity and are potential blog commenters.
Add to it that you're not going to remember the cases where people say "Nope, I haven't experienced fraud.", you're only going to remember those where people say "Money was stolen from me!"
Unless the reported incidence frequency is above the "normal" / average cases of credit card fraud or someone reports fraud on a card that was proven only to be used with PSN, I would hold off on blaming anyone quite so soon.
I'm holding off only because Mint loses its mind when I replace an American Express card. God, I hate Mint. Time to dump them, too.
Sony PlayStation Network Data Breach - Important Customer Information
You may have seen the recent news in relation to the Sony PlayStation Network data breach. Please be reassured that The Co-operative Bank treats data compromises extremely seriously. We do not believe at this time that enough information has been compromised to put your account at risk and therefore do not feel it necessary to block our customer's cards. We are however monitoring the situation and working closely with the Industry and will advise our customers if any further action needs to be taken.
http://arstechnica.com/gaming/news/2011/04/ars-readers-repor...
If I have the same username and password on another service, should I be rushing off to change my password right now?
My answer to this question is completely unaffected by the potential data leak at Sony: Yes. Yes you should.
Do you know that all the places you use that password for hash it correctly? You seem to be unsure (as is everyone else) on whether or not Sony stores passwords in plaintext, so why risk it? The only way you'll find out for sure whether or not you are at risk is if one of your accounts is compromised, so rather than waiting to find out I would take preventative action now.
Speaking from personal experience, your bank might not even tell you promptly if someone else has your card details, they might just block all the fraudulent transactions and not replace your card for six months.
and a question: could the solution be as simple as changing the CVV on the back of the cards?
But that's not the whole point: what is Sony doing to lessen the impact now that they screwed up?
Second, Sony did tell credit card companies and they do know about this. I called mine and the operator was well aware of of the data leak. They have been monitoring all accounts from the beginning.
Third, while you can always get a new card number for free, credit card companies tend not to issue new cards automatically. I've had it happen to me once before where they gave me a new one without me asking.
tl;dr These authorized charges are likely coincidental; the CC companies are well aware of the situation.
Did Sony know about this, or did they see a pattern of cards getting flagged that had PSN charges on them?
If the companies really believed the numbers were compromised they will send out new cards automatically. Like I said, it's happened to me before. I didn't have any suspicious activity or anything. But some company I did business with reported a credit card breach so my bank just sent everyone in the breach new cards with little letters telling them "you got owned, but no worries here's your new card."
If this happened to a smaller company, their ability to process would be taken away and after their infrastructure was verified, they would be forced to pay higher transaction rates.