Cards Stolen in Target Breach Flood Underground Markets
krebsonsecurity.com
krebsonsecurity.com
Then I realised that, really with all the flack it is getting, Bitcoin is such a solution. Once the conversion from $ to BTC is done, there's no way to get your credit card data or anything. You're practically immune against any data theft at the place where you're purchasing. Now, of course the problem only shifted as you have to guard your private keys now, but that's more or less a question of tooling and usability of proper BTC clients (which hopefully come up in the future). I'd rather have the valuable information stored in an open source application used by millions with strong code review, than in a closed source web app where an intern wrote the code in php and forgot the salt or stored everything plaintext.
This alone sounds to me like a pretty strong incentive.
I'm not trying to shill for Citi, I'm actually dropping them for other BS, but I assume other cards have it as well.
[1] - https://www.citibank.com/us/cards/gen-content/messages/van/i...
Thanks for the info.
The problem we are seeing is that it's often the big, legitimate merchants that are targets (ha) of high-tech theft. The kind of merchant for which you'd never think to use a one time use card.
With ShopSafe, each virtual card has a custom expiration of 2-12 months, a max spending limit (ex: $100), and only a single merchant can bill to it. That last feature is important as it means that even if it's leaked before the shorter expiration period nothing should be able to be charged to it. Recurring charges are possible though (ie the same initial merchant can charge you again) so you can use it for situations that require recurring billing. Either way the spending limit still applies.
Anonymity aside, I'd argue that virtual credit cards are even better than BTC from a consumer's perspective as you still have the power of charge backs. Each one has the same rights as your original card including the right to declare a purchase as fraudulent (ex: the merchant didn't ship the goods).
Would be cool if someone would create a physical version of these virtual cards that gets created on the fly for each transaction. I was hoping that Coin or one of the other "virtual physical cards" would do that but I guess that'll come later.
(yadda yadda weren't a bank, etc.)
Or was that just a sales pitch for BTC?
Arguably, prepaid cards from shopping malls aren't a good solution anyway. If you're paying for them in cash, then you'll never build up a credit history. And if you pay for them with your credit card... well then that's pointless since you may be buying them from the next Target.
Unless you rent or buy a home, have utility bills, rent or buy a car, etc. You don't have to use credit cards for retail transactions to build up a credit history.
The security of your credit card number is quite simply not your problem. It's up to the people who actually are on the hook to fix the infrastructure, and so far they still find it cheaper to eat the losses than to upgrade security.
Last week I got an email saying I made a $1,000 payment on my credit card. Except, I didn't. It wasn't bill pay time of the month. I brushed it off as a well formatted spam.
An hour later, it still bothered me. I logged in to check. Yup, there was a $1,000 payment recorded as of 4am my local time the same day. WTF? Oh, look, there's also fraudulent charges showing up now. How odd.
It turns out: my card didn't have enough free on the credit line for the losers to buy their xbox, so they called in and requested a $1,000 payment from my bank account on file. The credit card company happily issued it, my credit limit increased by $1,000, then the guy went out and bought his xbox.
While I was on the phone explaining this to the credit card company, three more fraudulent charges showed up in pre-auth.
Incompetents all around (except for whoever stole my credit card number).
The whole "stolen credit card number" doesn't hurt very much (since all bad charges are covered), but what really is annoying is someone getting away with purchasing things fraudulently.
Does your CC company not call to confirm things? Were the purchases clearly out of line with your previous purchase history (by location, type or amount)?
They called in to issue a $1,000 payment from my bank account (on file for recurring monthly payments) to the card. The phone rep allowed it apparently. (They later said the person who called in knew my family info and passed all "security questions." I wish I could have gotten a recording of that call to see if I knew who it was.)
Now, with $1,240 available on the card, they bought their xbox and other crap.
As a mater of principle, I had them refund me the $1,000 I didn't authorize. They sent me a check a week later and re-adjusted all balances appropriately.
Also points out a security hole; normally credit card companies are a lot less concerned about verifying identity when someone wants to make a payment on an account. Here's an example of why they should.
I remember seeing a news story about a gas company who had thought a customer damaged their gas meter. They replaced it, then deducted the $1000+ cost of replacement from the customers bank account. Since the customer authorized the ACH access, they were out of luck in getting the money back right away. If they hadn't linked their bank account, they would have gotten a bill and could have figure out an arrangement before handing over any cash!
In fact, some banks will not even give you an effective means of removing such authorization. You may literally need a new bank account to keep your account from being emptied in the future.
You give the bank's routing number and your account number to the utility or whomever. That's all they need. That information, by the way, is present in clear text on every paper check you write. The bank doesn't pre-authorize anything, nor can they block anything short of closing your account and giving you a new account number. Your protection is that presenting a fradulent check (electronic or physical) is a crime.
You can reverse ACH transactions by going to your bank and filling about a form and making a declaration under penalty of perjury. It goes back to the merchant as an R10, and the merchant usually deals with it in some other form, though if they've got a good relationship with their bank, they can dishonor the return.
That means nobody has a right to ask for money from my bank. I tell my bank whom to give money and how much. Not my credit card. Not my mortgage company. Definitely not my gym.* Nobody. Never.
Therefore I never used debit cards. Wells Fargo kept sending me debit cards when my ATM card expired. I changed banks. I do not want any ambiguity about the balance in my bank.
"But they promise me all kinds of protections!" That sounds nice, but there are two problems:
First, you are giving up a wonderful kind of protection: the ability to walk away. If I disagree with my credit card company, I can pay what I deem correct and cancel my card. They can see me in court about the remaining balance, if they think they can win. I am whole. I still have my money in the bank account. It is approximately never going to be a problem, because the credit card companies understand the score. They have a strong incentive to play fair with an honest credit card holder.
Second of all, the moment the bank/credit card company thinks something really fishy is going on, you are screwed. You know how you said you were wondering about those security questions and whether you would recognize the voice? Think carefully. If the bank suspects your nephew who stayed the weekend last month or a roommate or an ex-SO are directly involved, it all becomes your problem. The bank will not restore any funds to your account. The local police will laugh at you. And now you see the problem. The fact of your emptied bank account will not be changed, and those promises you were banking on are worthless. (Have money to hire a lawyer? That one is lose-lose.)
* Private gyms love to get bill your bank account and be authorized for automatic payment. The thing most people do not realize is most banks consider this to be completely and totally your problem now. If you cancel your gym membership, and the gym makes a "mistake" and keeps billing you, the bank will not help you. In fact, some banks will tell you that your only recourse (from their POV) is to get a new bank account to protect yourself in the future. Those "mistakes"? Your problem.
I frankly prefer not having to either deal with the automatic deduction or remembering to cut a check every month.
I had my debit card skimmed at a local gas station in October. Within a couple hours, it was being used at stores in Los Angeles. I live a 3+ hour drive from LA so there's no way the skimmer/data was physically taken down there–the data had to have been transferred (cell?) to someone down there pretty quickly.
My card was used at a restaurant and a few different stores, but several times per store. Total amount charged was about $2K. All purchases were < $100 and most purchases were for very even amounts at drug stores. Based on research, this is because buying gift cards is a favorite use of stolen cards. Gift cards can be turned into cash online for about 75-85 cents on the dollar.
Chase was very good about freezing the card and crediting back all the fraudulent charges.
TIPS:
- Use cash or a gas card for gas OR at the very least, use a pump close to the cashier
- Debit cards have a reputation for having less protection than credit cards. At least at Chase, this is no longer true. Chase has zero-liability for unauthorized debit card purchases [1]
- Check your online banking often
- Don't rely on your bank's automated fraud detection. Most alerts I've received from Chase have been false positives (legitimate purchases while traveling).
My response: "You are calling me at my California home number. I WISH I were in Waikiki right now. How about you reverse everything today and send me a new card in the mail?"
I was buying a custom-made suit at Indochino's "traveling tailor" event. It was at a pop-up storefront in Seattle (where I live) but my bank thought their mobile point-of-sale card processing system was in Vancouver, BC and declined the transaction until I explained to them what happened.
And the suit? It's wonderful.
On the one hand, I had a number genuinely stolen a while back in the PSN hack, and a case where someone tried to use my debit card in a hotel in Tennessee. In both cases, I got a phone call almost immediately, was out zero dollars and had a new debit card number within 24 hours.
On the other hand, I travel a lot. Emphasis on a lot. And I have begun simply planning trips around the expectation that at least one of my BoA cards will be frozen every time I do so, because their systems don't seem to actually work off usage patterns. Instead, use of the card beyond a certain mileage radius from home address triggers a fraud alert. So even though quite a bit of my travel is to a small number of cities, I still have to deal with occasional random fraud alerts freezing my cards (example: I've been to Washington, DC around six times in the past year. Despite that -- and despite making the booking in advance, including the card number -- I still had one of my cards frozen when trying to check into a hotel there a while back).
Their customer service people have confirmed that it's just mileage radius, and anecdotally it seems that the radius is around 600 miles (I am based near Kansas City, and can safely use BoA cards in Denver and Chicago, but has a problem once in Austin, IIRC). Which probably makes sense for most people, but I am more than 600 miles from home at least a couple times every month. And there seems to be nothing for it aside from calling their fraud-prevention department every time I'm about to go somewhere, which is equally impractical.
Imagine if someone steals your debit card number and you did not find out about it for a week. By then you could miss your next rent payment because you don't have available funds in your account.
At least with a credit card, you have a full statement period to clean things up.
My guess is there's a significant chunk of the population who, like me, simply don't own any credit cards. A quick search puts it around 25-30% of the US population. People do it for various reasons (don't qualify, don't believe in using them, etc.).
Debit cards are a convenient tool for these people.
[I realize the parent didn't indicate that they themselves were in the "no credit card" camp, just thought it might be helpful information for someone].
Debit cards do not have "a reputation" for having less protection in America. Debit cards do have less protection in America. With a credit card, you can lose $50. With a debit card, you can lose all of the money in your account and in all accounts linked to that account.
Chase has a policy of advertising zero-liability for debit cards. The US government has a federal law requiring $0 to $50 liability for credit cards ($50 if you lost the physical card and didn't report it before it's used, $0 otherwise). The US government has a federal law requiring tiered liability for debit cards depending on how fast you report a theft and providing no protection after 60 days. [1]
Meanwhile, bank policies may appear to offer better than federal law requires for debit cards, but in practice the fine print can ruin you, and it's up to the bank whether you get protected under their policy since it's not federal law, and at best you get arbitration to settle a dispute not a court.
See, for example, the exceptions Chase gives themselves in their 'zero liability' [2] & [3]:
"If your Card is lost or stolen, or your Card number is used without your authorization, if you notify us promptly, you are not liable for any unauthorized transactions, including transactions made at merchants, over the telephone, at ATMs, or on the Internet. However, these special provisions do not apply where you were grossly negligent or fraudulent in the handling of your account or Card, where you have given someone else your Card, Card number, or PIN, or where you delay reporting unauthorized transactions for more than 60 days."
"You must provide us with all information we need to investigate the alleged error or item. You must also file any police reports and provide any supporting affidavits and testimony we reasonably request. If you do not comply with the requirements above, we are not required to reimburse you for any claimed loss, and you cannot bring any legal claim against us in any way related to the item or errors.
"You must notify us in writing within 30 days after we mail a statement or otherwise make a statement available (for example, paperless statements) if . . . An item that you did not authorize or that is altered is listed on the statement ... You must provide us with all information we need to investigate the alleged error or item. You must also file any police reports and provide any supporting affidavits and testimony we reasonably request. If you do not comply with the requirements above, we are not required to reimburse you for any claimed loss, and you cannot bring any legal claim against us in any way related to the item or errors."
[1] http://www.consumer.ftc.gov/articles/0213-lost-or-stolen-cre...
[2] https://www.chase.com/online/services/document/deposit_accou...
[3] https://www.chase.com/online/private_client/document/supplem...
Do you have any record of any credit card company trying to take that perceived out, ever?
It would be a strange thing for them to do, since they don't eat the costs of fraud anyway (the merchants do).
What?
I have contested charges on a debit card before. You don't go anywhere near having an arbitrator. You call them and explain the situation, they mail you an affidavit, you mail it back, money reappears.
These aren't theoretical/untested waters. People file chargebacks on debit cards all the time. The only downside (compared to credit cards) is that the money has left your possession until the bank puts it back (rather than you refusing to pay the charge until it goes away).
I don't know of any bank that don't offer this now. As part of FDIC Regulation E, the cap on consumer liability for credit card fraud is a max of $50 [1]. For most banks, it costs them more than that to try to get that from the consumers .
The reason why people say that debit cards are safer than credit is because credit card provides a buffer to your bank account. If there is fraud, you still have the cash while the fraud is investigated. With debit, you are out the cash until the fraud is reported.
[1] http://www.fdic.gov/regulations/laws/rules/6500-1350.html ____________________________ (a) UNAUTHORIZED ELECTRONIC FUND TRANSFERS; LIMIT.--A consumer shall be liable for any unauthorized electronic fund transfer involving the account of such consumer only if the card or other means of access utilized for such transfer was an accepted card or other means of access and if the issuer of such card, code, or other means of access has provided a means whereby the user of such card, code, or other means of access can be identified as the person authorized to use it, such as by signature, photograph, or fingerprint or by electronic or mechanical confirmation. In no event, however, shall a consumer's liability for an unauthorized transfer exceed the lesser of--
(1) $50; or
(2) the amount of money or value of property or services obtained in such unauthorized electronic fund transfer prior to the time the financial institution is notified ____________________________
Same link, one paragraph down: "Notwithstanding the foregoing, reimbursement need not be made to the consumer for losses the financial institution establishes would not have occurred but for the failure of the consumer to report within sixty days of transmittal of the statement (or in extenuating circumstances such as extended travel or hospitalization, within a reasonable time under the circumstances) any unauthorized electronic fund transfer or account error which appears on the periodic statement provided to the consumer under section 906. In addition, reimbursement need not be made to the consumer for losses which the financial institution establishes would not have occurred but for the failure of the consumer to report any loss or theft of a card or other means of access within two business days after the consumer learns of the loss or theft (or in extenuating circumstances such as extended travel or hospitalization, within a longer period which is reasonable under the circumstances), but the consumer's liability under this subsection in any such case may not exceed a total of $500, or the amount of unauthorized electronic fund transfers which occur following the close of two business days (or such longer period) after the consumer learns of the loss or theft but prior to notice to the financial institution under this subsection, whichever is less."
Whereas with a debit card, the money has effectively disappeared from your checking account until the chargeback process completes.
Yes, but it may be a couple of very stress filled weeks until you get your money back. It'll be even worse if you don't have cash elsewhere, or credit cards you can use for everything in the meantime. If you're one of the people who only have a debit card, well, you're screwed.
I called them up to proactively report it stolen - the problem is they will immediately deactivate your current card and it takes 7-10 business days for the new one to show up. It is not possible to get a 2nd card number without deactivating the first (to avoid a no-card for 2 weeks situation). Or you can have them overnight it to you for $16.
Kind of annoying to pay $16 for a merchant error, or to not have your primary card for 2 weeks during the holiday season (and also the card you use to pay all service bills like cable tv, internet, city/trash/water etc).
Ultimately I decided to do nothing and just keep a close eye on account activity until January when it is less inconvenient to wait for the new one.
Since they by default send a push notification on every transaction, it'd be overkill as long as you respond quickly in the even of an unauthorized one.
[1]http://www.simple.com [2]simple is fantastic for a whole host of reasons. Check them out. I'm not affiliated in any way, but have been using them as my primary bank since early on in their beta.
I find myself wondering how this might affect Target. I almost never shop there myself. My wife, on the other hand, might have shopped there once a month or once every couple of months. Yesterday she told me she is not going back. Ever. There have to be other people on the same boat.
It'll be interesting if they ever release information on how exactly the breach was orchestrated. My biggest question is about all of that data moving about Target's distributed system without any encryption whatsoever. At least that's what it sounds like. The data capture had to be done at some central point in their infrastructure in order to affect some 1,800 stores.
Again, all of that data from 1,800 stores got to a central repository of some sort completely unprotected? Why isn't that information stored and limited to the within the walls of each store? It'd sure limit the exposure, well, a factor of 2,000. Anything leaving the walls of a store needs to be encrypted.
Perhaps someone with more experience in brick-and-mortar payment infrastructures of this kind can comment on this?
Target is just too large to really be impacted in the long run - however it's going to have a nice impact on their current holiday season.
The information can't only stay within the store, because purchases from one Target may be returned at any Target, and they may look up receipts by credit card used. At Target's scale, it makes more sense to do a centralized lookup (or local + centralized), rather than a query to every store.
The likely scenario in this case is that Target uses a central hub for credit card processing, so there is probably at least one server that briefly looks at all of that credit card info. And if an attacker is able to install malware on one or more of those servers, they'll be able to silently record all of the card data as it comes in; even if it's completely encrypted to and from the server, the server itself will need to at least briefly have an unencrypted version of it in memory.
Basically, scenarios like this generally only happen in a deeply intrusive breach.
Why in the world would they do that? I would lose a lot of sleep over if I had to store just name and card number, but at least I could see some use for that. For example, you could look up a customer’s past purchases for returns or warranty claims.
Why did Target want to store the expiration date, so the card could be used on online stores that don’t check CVV2, and the magnetic track info with CVV1 so the cards can be cloned?
--
Edit: if early reports are accurate, and the credit card data was stolen via malware on the POS machines as the cards were swiped, then it would make sense that they would capture every possible piece of data, including CVV1.
Great service and I didn't even have to do anything.
Cheers simple!
I have other cards I can use, so it is not inconvenience. I feel I dodged some trouble.
Your question reminded me of this and I see someone already responded. In any case you should get a new card if there was a chance you were affected.
This is going to get macroeconomically expensive, I think.
No fucking way (pardon my French)!
I haven't seen anyone comment on this yet, but doesn't this seem incredible? I.e. I don't believe it.
Am I to accept that transfers of $20,000,000 to $100,000,000 ($20 to $100 times a batch of 1 million) are occuring in payment for these cards.
Bullshit. I just don't believe it. This theft is now widely known. So no way that someone is going to plunk down $100,000,000 just to get a small portion of this info.
Again, bullshit. IMO. It just doesn't make sense.
No one is buying them in the millions. But plenty would buy 10, 20, 50 good stolen card numbers.