Largest Coordinated ATM Rip-off Ever Nets $9+ Million in 30 Minutes
networkworld.com
networkworld.com
$9,000,000 / 130 ATMS = $69,230.8 or roughly 692 $100 bills.
The US government requirement for currency paper is: "the thickness of the paper shall be 124 micrometers [...]."[1]
124 micrometers * 692 bills = 0.085808 meters or 3.38 inches thick. Not bad at all.
[1] https://www.fbo.gov/utils/view?id=ccca3ea58d649385700a9f20c9...And most non-casino ATMs have a per transaction limit of $600-$800, independent of your card's limit. You can do multiple transactions, but you'll get $20s every time. This too varies a bit in Vegas and AC, where you can find much higher limits, but again only in the right ATMs in the right casinos.
Vegas casinos have a rule that they will only trade you up to $500 in $100s for lower denominations per casino per day. It's to prevent laundering. The Feds absolutely hate $100 bills because of that. If the FBI were able to get rid of them, they would in a heart beat.
Since I made most of my money playing online poker and withdrew it that way, I would often spend hours each day walking up and down the strip cashing $20s in for $100s.
I've never understood why $50s weren't used more. It seems like the optimal bill. Spitting out $500 in them isn't objectionable, and I imagine a lot of people withdraw $50 (or would if you made it a quick cash option).
They must have choses extremely busy ATMs, or whoever got the scoop on this story got something wrong.
If you walked out with a fistful of cash, what would motivate you to give most (some?) of it back? The promise of more money in the future?
People involved in online fraud rarely collaborate with each other. You never know who's on the other end and your anonymity is your biggest strength. It's more of a marketplace where you buy cards, skimmers, or accounts from vendors and then go out and use them on your own.
Some guy probably sold these cards (or just the data to encode them) at a hefty price with the disclaimer that they had to be used on a certain date and time at any ATM.
The benefit to him is his increased reputation. You can't survive in these circles unless people vouch for you. That's why, when you read articles about darkmarket, they talk about reviewers who inspect products from vendors. This guy just sold products that netted $9,000,000. Everyone is going to want to buy from him now.
Don't think that there's nothing in it for the vendor. ATM skimmers sell for $7,000. If he pulls this off again, people may just buy the cards from him for $10,000 each for a 700% return. That's not too shabby for sitting on your ass and not taking the risk of being on the streets.
I just don't believe that this was structured like a traditional gang. This level of organization in online fraud is completely unprecedented. There were more than 6 cities hit in numerous countries, I don't see them recruiting that many random people to participate and having profit sharing since gangs are tight-knit.
It's fascinating. Basically, the cashiers are working on the honor system. They get to keep a percentage (this guy gets 40%), and they send the rest to the "boss" through e-gold. The percentage you get increases as you earn their trust. I guess that this keeps most people honest, as they want to get a higher percentage the next time.
Yes, you can often hire a cashier. Typically, this guy has some plastic and an encoder, but he doesn't have a steady supply of data to encode the cards. He's working with you because you have data to cards with a high limit and you can verify that they're valid. Most of the time, he's not even on the street. He'll encode them in the car and have someone else run up to the ATMs.
[1] http://web.archive.org/web/20061115154615/http://smallworldp...
Also, correcting people for minor mistakes on forums is very annoying.
The article calls them "cashers."
Think about the math, as well. They took $9m from ATMs.. how many people could they possibly have been using? Even with 1,000 "cashers" (highly unlikely), thats $9,000 each... far more than just 1 run to the ATM.
What they most likely did, or at least what I would do, is get a map of ATMs, find the points which yield the least weighted distance to the most ATMs (an NP problem, but very much worth it in this case), and set-up a "re-up" station there. Instruct your cashers to return their used card to these stations, along with the bundle of cash (or maybe x% of it), and you'll give them another card. Good worker ants.
However, something seems off here. $9m from 130 ATMs, that's $70,000 per ATM. With a max of at most $1,000 per transaction, thats 70 hits per ATM. In 30 minutes. So you mean to tell me each of 130 ATMs was hit for $1000 every 30 seconds?
Something is off about that. I think they're underreporting the number of ATMs or inflating the amount stolen.
Also, cashing out ATMs is very hard work. You need to use a skimmer to capture someone else's card then copy it to your blank plastic. It won't work if there's an electronic chip in it, like many countries (mostly in Europe) already have. Then you have to work within the usual transaction/account limits. You'd be lucky to get $2,000 off of one card. Basically, the next card seems like nothing when you have a fist worth $70,000.
I think the key to all of this is in the payroll card. It might not be bound to the traditional credit/debit card limits. Perhaps it's throttled at a central point and the guy who already has access to the RBS WorldPay systems was able to lift it.
There's no need to use a skimmer to capture someone's card, or anything like that. If you have the account information (likely encrypted), you can simply print it onto the magstrip of an ATM card. It's very simple. They had access to accounts, and they had control to put imaginary funds into those accounts, which could be withdrawn.
The real problem they faced was that once they executed this, it'd be noticed by the bank and/or payroll company once they realized things weren't square, that is, once they realized money was coming from thin air.
I think you're greatly exaggerating the scale of this. If I said I could give you an unlimited ATM card, and all you had to do was get on a plane to another city, would you do it? It didn't have to be multiple languages.
The point is, the hackers knew they struck gold, and they organized a mass ATM hit. If you know the hackers, and hell, they could even show you once or twice, then you'd be willing to scrap together a team to help out.
I think trading cash for another ATM isn't that bad of deal. You'd essentially get paid per card used with no end in sight. You get a card, you extract all money, you return money (keep some for yourself) and get a new card. At the end of 30 minutes, you have more money for yourself than what any 1 card would have given you.
At any rate, when you invent money out of thin air, there are plenty of ways to make it so everybody wins.
I outlined how I think it happened in a couple of other posts.[1][2] It wasn't organized drug-gang style where you have people go out and come back to you with money because there's no such structure in online fraud. 99% of the time, online, accounts are sold and whatever happens after is at the buyer's discretion. In my experience, there's never a high-level of collaboration. You can't form teams just by asking people if they want to steal money with you.
Single-page print version: http://www.networkworld.com/community/print/38366
(I suppose it was probably done at night when things were quiet; makes you think what you would have done though!)