In Hours, Thieves Took $45 Million in A.T.M. Scheme
nytimes.com
nytimes.com
If true, that's hilarious. Seriously, ATM reading magnetic stripes? What century are we, again? It seems I've traveled backwards in time. Either that, or it's a new Terminator movie plot.
I haven't seen a credit or debit card without a smartcard (which requires a PIN) in Brazil in more than a decade now. Not sure if it would have stopped this particular attack, as the magstripe readers are still there because of foreign credit cards. However, there are stricter restrictions on foreign money withdrawals which are enforced regardless of the originating bank.
If the US would switch to chip and pin then all those countries that already use chip and pin can turn off the magnetic strip by default. Right now they need to leave it on as the US is common travel destination.
Chip and pin isn't 100% secure either but it would stop a large number of skimmers.
If you don't travel and you live in a country with chip and pin have your bank disable your magnetic stripe. Even if someone were to skim your card the bank will not authorize a transaction via magnetic stripe.
The mag stripe is as safe as giving everybody your CC number (with CVV code)
Which chip-and-pin two things happen:
- the chip won't work without the pin number being input
- only one transaction is authorized at a time
- the chip is not duplicable (the information needed to duplicate it can't be read from the card)
http://www.justice.gov/usao/nye/pr/2013/2013may09.html
I could not locate a copy of the actual indictment, so if somebody could find a link to it I would appreciate it.
I was curious to how they were caught. That they only caught the runners (the guys going to the ATM's with cards) and not the group leaders or the hackers suggests they were caught via traditional ID methods via ATM cameras[1], mobile phone or car license plates.
The other evidence to support this theory is that the runners in other countries were not arrested or charged at the same time. If law enforcement took these guys down from the top, you'd think they would be able to also ID the runners in other countries.
Instead, only the group of runners organized around New York were caught - 8 people, out of a group that would number at least 50 or more.
I also don't understand the money laundering charge. The defendants deposited $150k in $20 bills into a Miami bank and then used the account to buy a car. That isn't doing a very good job of hiding the source of funds, if that is what their intention was.
Seems very amateur and unworthy of a professional criminal organization - more likely it was the proceeds of a cut that one of the runners got.
[1] During the Boston Marathon Bombing manhunt the Feds released pictures that were taken from an ATM showing Suspect #2 (later identified as Dzhokhar Tsarnaev):
http://i.imgur.com/0ZF7ud9.png
From the pictures you can see that ATM's take a photo when the user is approaching and while they are using the ATM (the first picture seems to be triggered by the door being opened). The quality is surprisingly good.
> The hackers – who are not named in the indictment – proceeded to raise the withdrawal limits on prepaid MasterCard debit accounts issued by the National Bank of Ras Al-Khaimah, also known as RAKBANK, which is in United Arab Emirates.
Same card being used within seconds at two locations 5 miles apart? Probably something funny going on. "Deposits" of millions of dollars on a single pre-paid card in a day? Might be unusual.
These banks deserve to lose every dime they have to lose if they are this stupid, or are hiring such inept IT people.
major banks here all made at least a trillion in profit last year but couldnt be arsed to pay for legit IT staff. now we all suffer paying tax dollars to track down all these thieves who easily fraud their faces off with the terribad security and poor code quality
So it's possible to scam the system, but the banks probably figure that they would lose more money in lost transaction fees by implementing a 100% secure, ACID-compliant 2-phase commit payment protocol, than by keeping the current best effort authorization + batch processing system in place.
Actually, no. No approval code (which is obtained from the network), there is no purchase.
The transaction is stored, and fowarded later. It's a variant on the Card Number + Impression that used to be common place 20 years ago, and Card Number + CCV that is still common place in locations with intermittent/no connectivity.
The prime example of this being done electronically is on planes, they have been accepting credit cards a large number of years before connectivity was possible.
Don't forget that the banks make their money from ATMs off the transaction fees, so if a foreign customer's bank is unreachable at that moment, they may still take a chance and give them their money (plus charge them the $4).
Do you work in banking and know about this, or are you making assumptions about how payment terminals work?
Simply sum all withdrawals, not per card number, but per financial institution (per BIC-code), and measure the money flowing out per time unit. If it exceeds a multiple of X times the average for what's normal on that day, raise an alarm to investigate manually.
Such velocity checks would never work if only looking at withdrawals in a single ATM and still not good enough if they would measure all withdrawals in a single banks all ATMs as there are so many banks.
Banks need to cooperate in developing a global anti-fraud system. Unfortunately they still use COBOL and don't lose enough money on these things to find the motivation to do it.
It maybe because the vulnerabilities still exist and they don't want the general public to know about it. Yet this rings hollow as the bad guys still know about it.
> Prosecutors said the scheme involved attacks on two banks, Rakbank, which is in the United Arab Emirates, and the Bank of Muscat in Oman.
http://www.smh.com.au/it-pro/security-it/massive-21stcentury...
edit: Oh, the NYTimes version of this story says it's a US based credit card processor name withheld http://newsdiffs.org/article-history/www.nytimes.com/2013/05... Other versions say the foreign banks themselves were the credit card processors http://mashable.com/2013/05/09/atm-hackers/
[1] : http://cbsnewyork.files.wordpress.com/2013/05/lajud-13-cr-02...
Not sure about the other one, the bank of Muscat site is a bit crap, didn't find mention of the processor in the T&Cs or description of the cards [2].
[0] https://www.rakbankprepaidcard.ae/CustomerPortal/WebPages/Lo... [1] http://www.electracard.com/contact-us.php [2] http://www.bankmuscat.com/cards/prepaidmain.shtml
[0] http://www.controlcase.com/ [1] https://www.pcisecuritystandards.org/
I am sure that the crew here att HN could come up with 50 better solutions to security than the magnetic strip and a string of numbers.
I guess they've either been stung enough by fraud up there that they switched over from stripes, or they're just a bit more forward thinking than we are.
This reminds me of a Canadian syndicate from a few years back... never caught the top guy (rumored to be British).
Any followers of the Pink Panthers out there?
http://www.theonion.com/articles/after-checking-your-bank-ac...
These people have international reach, were able to recruit people to run the ATMs for them, and the ostensible "ring leader" was assassinated.
Either organized crime and/or former government agents with cyber security and cyber-spying training.
---
This actually got me thinking about a relatively straight-forward way to make ATMs more secure. Many ATMs have cameras and are, presumably, recording each time someone makes a transaction. I don't know exactly how the system works, but here's what I think:
- People who use ATMs should pretty much expect to be recorded in some fashion for security purposes, even if it's just a camera in the corner of the room.
- By using an ATM most people, even the privacy-conscious, would agree to this amount of surveillance. If not, they are welcome to visit their bank during regular business hours, in a ski mask if they prefer, or better yet use the inside of their mattresses instead.
- Adding a camera to a device, particularly one like an ATM, is trivial to implement and should only make a slight difference in cost.
- This camera could also be sensitive to infrared or other bands in order to defeat the ski-mask (thieving) or eye-patch/bandage (handicapped or disfigured) crowds.
- The software could be made such that it only proceeds with certain actions IFF it recognizes that the camera is not being blocked, that it recognizes a face, and that the face is not being spoofed by a Polaroid or something silly.
- ATMs are networked and should be capable of uploading medium resolution photos. Assuming reasonable policies could be maintained, the photo could be sent over the wire directly to your card-issuing institution and then routed to you, perhaps with a 7-days-til-self-destruct mechanism. Obviously you could archive these if you wanted, but the point is that banks/credit companies would treat it the same as security footage, i.e. data glut that's only useful while it's fresh.
- As soon as you are made aware of some sort of fraud, you can simply report the transaction, with identifying snap, to the bank (who will hand it over to authorities).
I'll leave the potential problems of this system to your imaginations, but it seems to me like a fairly easy to adopt solution to small, regular ATM theft. Obviously a coordinated attack could perhaps find some sort of exploit, but maybe it could deter the small-timers enough to be worth it.
EDIT: I am aware that this doesn't solve any of the particulars in the article, but I still think it's "on topic" since we all like tech, and ATMs are tech :)
2) The vast majority of ATMs have cameras. I would guess (only a guess) that all of the locations they hit had cameras to pull the max amount of cash.
3) If they didn't have cameras in the ATM, they were certainly cameras nearby. Likely the mistake they made was covering their face, but using a vehicle (since they had to hit a lot fast) with a mask on and some other camera got their plates.
But..., your idea of using not just visible light has merit and I hope someone figures out how to implement it.
ING Direct does exactly this!
I get an email (text messages possible too) every time I make a purchase over a certain amount that I've chosen. You can set the limit as low as $1 if you really wanted to, so you can be notified of literally every single debit card purchase.
This forward thinking is one of the many benefits (no fees EVER being another) I've enjoyed and why I love banking with them.
Online banking is definitely the future, or at least will grow to be a much larger part of it.
The functionality you're talking about is obviously much more useful :) I'll have to check and see if my bank has this function, as I probably would not have set it when I opened my account and have yet to receive anything like it. My girlfriend's bank sends her a message when her account is under a certain amount and flat out denies withdrawals over that same amount (i.e. notifies when under $500, can't withdraw more than $500/mo regardless).
Chase as well.
Because there is no cut off, other than turning off notifications, this sounds like it could be annoying. But in practice, it’s just nice, and gives you a sense of security.
And when looking back over transactions at the end of the month - the maps are dang handy for jogging my memory…
Whenever I get an email from ING about a transaction or deposit (one that isn't totally obvious) I do this:
Click "Forward".
Delete all text/images.
Write a few words about the purchase or deposit.
And send it to myself.
That way I can look back in Gmail at any time and know EXACTLY what I spent that money on. This is helpful because sometimes knowing WHERE I spent money doesn't tell me anything about I actually purchased.For example, I have a Debit Card Purchase of $10 at Farhad Monadjeem. What in the HECK is that???? Oh, that's actually the car wash at Mobil; the owner's name I suppose. This system is also great for online purchases, so I don't have to login to various websites to see what item(s) I purchased; it's all in my email.
Easy and extremely effective!
Right now I only use the direct deposit alert so I know when I've been paid and the security alerts.
Meanwhile, LIBOR, but I'm sure the banks will spend millions ensuring that these hardened crims spend the rest of their days behind bars.
They had a field day (or months). Police estimated that the person had withdrawn up to $2M from ATMs.
But people are greedy - faced with a machine that effectively gave free cash, as much as desired - how was this person caught? A gambling spree (go figure - where's the real allure in "winning" when you can "win" at any ATM?) - on a losing streak, he couldn't be bothered to spread his withdrawals amongst multiple ATMs at or around the casino, and in one night emptied an ATM (approximately $100,000), which tipped off the bank, that had only filled it that morning. Some cross referencing, and it was all over.
Scarily, the bank noted that until then, there was "nothing that had been flagged in their system" alerting to a problem with this person/account.
- A camera in the corner of the room is vastly different in its surveillance capacities as a camera in front of your face.
- People are not used to seeing cameras in front of them at an ATM, only on the wall behind them. In fact, a camera attached to the front of an ATM could very well be part of a skimming device.
- Banks are always looking for a way to hold you responsible for their fuckups. For example, it can be more difficult to dispute a debit card transaction if your PIN was used. Your bank can and will use the photo evidence against you in the same manner, unless you can prove beyond a doubt that it wasn't you.
- ATMs are networked, but not necessarily with high-bandwidth connections.
- The "authorities" can and will archive those photos and use them for questionable purposes. You're deluding yourself if you think those photos will self-destruct.
- Cameras are already on every bank ATM I've used in recent years. Usually, they are on the other side of a two-way mirror. It's no secret what's behind it, but I'm sure they get a really nice shot of anyone who wants to check their lipstick in it really quick. That being said, I've also seen plenty in the delis around that have a very blatant camera installed directly above the screen.
- When do you foresee this being a real issue? I agree that it would be very difficult to fight, but isn't that the point? If someone manages to spoof your card, your pin, and your face all at the same time that seems like a much different problem (like a hostage...) than simple fraud. I'm having trouble envisioning how such a system could work directly against you in the way that you suggest.
- True. Then again, compression technology is such that even an ATM on a dial-up modem could probably upload a useful snap by the time you could finish a transaction. I do think it's reasonable to expect that if the system were to be implemented that in a few years time all ATMs could be running on decent connections. Even if you count the few real backcountry areas with ATMs, it's a small issue.
- The rest of my comment will address your last point so that it's a little more readable, and because I think it's the most important to address.
First, if you believe this to be the case, then it's already too late. Your face is already in their databases doing perhaps all kinds of more interesting things than depositing your paycheck. This falls back to the issue of if you don't trust anyone, don't depend on anyone which ultimately leads to non-participation being the best bet for avoidance, or over-participation in order to blend in. You should probably worry much more about what the "authorities" are doing with your candid shots on facebook, your friends' facebook, or whatever than the pic snapped of while you withdraw $40 for an evening on the town.
The most obvious line of defense is, like the whole gun database ordeal, to stipulate that no government body may keep a record of this data beyond its expiration date and even then, only by the institution to which it is served unless directed otherwise by a warrant. If you're worried about your bank doing dirty things to your image, you might want to stop banking since they already have a copy of every other relevant bit of identifying data. If you're worried about the police, then you should be worried about the NSA. If you're worried about the NSA, good. Let me know once you've found a nice hiding space, I'll bring some board games. I don't expect we'll have much internet access.
You'd be right if you said that the stipulation would mean nothing to those interested in gathering that information, but the point is really just to prevent them from using that information in any way that's detectable.
When I say self-destruct, what I mean is the bank's copy. They have no reason to keep it, but sure, maybe the government does. But again, if that's the case then I'm sure they would have had a backdoor to the live feed of all those existing ATM cameras anyway.
---
Sorry if that was a bit rambling, but I hope you get the gist. We share some of the same concerns but in my opinion, it's already game over unless we can bring more information into the equation. That data is already out there. Your photo is already on the ATM and every security cam you walked past to get there. The best thing you can do is to have a copy of that information yourself because right now you know less than they do, and that's how you lose.
If you are willing to sign up to https://moneycenter.yodlee.com/ you can setup such alerts.
So this just reminds me of the Microsoft paper a few months back - the problem is not robbing the electronic bits, the problem is getting them out of the financial system.
In the traditional bank transfer they need a money mule stupid enough to transfer to a Russian bank. In this one the people with the (inside) knowledge to uncap 12 cards needed to find 100 guys walking up to atms, plus their supervisors and contacts.
So it seems either you can rob a bank but need an idiot to help you get it out the country, or you can rob a bank and need a guy who happily sends hooded killers round to your place.
All for what Zuckerberg sees as small change.
Well anyway, I'm just going to take a little trip on the Information Superhighway, I'll be back later.
See the problem?
Shameless plug: Brother's Canadian startup
It's the system of insurance that is broken, not the fact that dumb corporations are doing stupid things and losing other people's money.
Socialism doesn't work in any system that you implement it in. When you separate the consequences from the actor, the rational actors will behave in a maximally self-interested way and screw everyone else. When all do this, the nation falls back 100 years. Not remedied, the nation falls back 1000 years.
This money comes straight out of their value as a business. It is a loss to the shareholders.
Say for example there was a regulation that said banks couldn't increase fees because of theft (as a thought exercise, not a practical suggestion). The 45 million loss would directly affect their profits. Lets pretend this happened on a yearly basis on average, it makes good business sense to spend 20 million a year on security to prevent it happening.
If they can lose 45 million a year but know they can recuperate 30 million by making the customer cover the cost of losses, it becomes cheaper to charge the customer than invest in security.