From my understanding CVV/CVCs are a function of the PAN, expiry, and some DES encryption. Does this mean that the target bank had a weak DES key or was some other vulnerability discovered?
I guess he didn't discover how to break the secret code of the card, and the transactions were flagged by the server immediately. Some servers flag the card secretly, so credit card thieves have more problems to validate the stolen cards.
The press article claims it was something impressive, but my guess is that it's just a bad report by the police or by the journalists.
> In other notes, he had left a record of how he had managed to obtain the security codes of the credit cards