Who's Selling Credit Cards From Target
krebsonsecurity.com
krebsonsecurity.com
With that being said, I don't see how Krebs reaches the conclusion that this guy "probably" knows who stole the Target cards or how they were stolen. They were just posted on his crappy carding forum.
It seems a bit disingenuous to me to plaster this person's dox under this headline; yes, he seems pretty scummy and runs several criminal enterprises but there's no actual evidence in the article linking him to the Target fraud beyond someone else using his forum to hawk their stolen goods.
In my opinion just get a new card, don't wait for suspicious activity. Check it to see if it was already used. Also given that the 3 letter pins weren't from the back are not included I'm not sure if it's going to be very easy to make use of this card data. Having said, still get a new card if you used it at Target recently.
Many merchants require the CVC code to protect themselves against fraud/chargebacks and because they can get lower processing fees, but strictly speaking, it's not necessary to make a transaction (IIRC, the only thing you need is the card number and expiration date).
Notably, Amazon does this for their 1-click checkout. Saving CVC codes is against PCI compliance, so in order to provide that low-friction experience, they simply post the saved card information without it.
If the dollar amount charged is low enough you don't even need the expiration date. You just use the current month.
We've frequently have to charge expired customer credit cards (expired by years in many cases) and as long as the dollar amount is low enough (off the top +- $40 [1]) and the card number hasn't been changed the charge will go through. Very convenient instead of having to contact the customer to get a new credit card expiration date. Also helps because that way you don't give the customer a chance to rethink what they are paying for and whether they need it or not.
[1] May be higher but I'm not certain if it's $60 or $100 so I will go with an amount that I know works.
Some of these were from banks that would let you try to login given a card number and password, and told you on failure if you got the card number wrong or the password wrong, so I was able to do a check using that on some of the cards and found they were legit card numbers for accounts at those banks.
This was on a Friday late afternoon Pacific time.
I called the FBI to see if they were interested. They were not, and suggested that the Secret Service might be more appropriate. The Secret Service was also not interested. I then tried the credit card associations, and most of them told me that this would be an issue for their security department and suggested that I call back Monday morning as the security department had gone home for the weekend. One did give me the email I could forward the mail to.
I had thought someone would be interested in this, at least enough to want to look at the card numbers I had to determine if they came from a known breach or were from something new.
Is it possible the CC companies are worried that if the government steps in, it reduces their role in anti-fraud and helps their competitors?
Last year, I had four fraudulent transactions appear on my card. I am a very cautious user - Linux on the desktop, seperate user and browser profile for e-shopping etc. This was the first time it happened in over 15 years of extensive online card-use.
Two of the transactions were with Netflix to register new streaming accounts. I called up Netflix, and within a couple minutes had a block placed on my card and both the accounts deleted with refunds to my card.
The other two transactions were on frys.com. One was for a laptop and the other, much higher value, for a smartphone. Shockingly enough, while one transaction got security flagged and did not go thru, the laptop one cleared and the laptop had been shipped out before I contacted frys. Frys rep told me on the phone that the information submitted was very clearly and obviously phony - the email address was a string of random letters @gmail.com, name etc everything was fake. Even with the credit card info, the only piece of correct info was the credit card number. No CVV was submitted, no correct billing address, not even the name on the card was correct. Heck, as my credit card is NOT US based, even the country of the card was not correct. Yet Frys shipped it.
I tried to get more information about the fraud but frys refused: they told me point blank, that they will not give me information, they will not initiate a police case, and they will not refund my money even though they were clearly at fault for having the transaction to go thru.
I, not being based in the US, had few options. I filed an online police report with San Jose police, where Frys is based. I also filed an online report with the FBI online fraud division. Both of them assumed I was filing these reports for insurance/reporting purposes, but told me outright that no investigation would take place.
Later, when my bank provided me with more info about the fraud I found out that frys actually challenged my chargeback and provided the transactions details to my bank. As expected they had no case, but I found out from the details that the laptop had been shipped to an address in Abilene, TX. I immediately registered an online report with the Abilene PD as well.
None of the authorities were interested in following up. Considering how trivial it would have been to atleast checkup on the address, this seems like a bad lapse.
I believe it creates a moral hazard: In the end, frys was the one that was out a few hundred dollars, and they refuse to prosecute. Police does not act on my complaint. Once it becomes known that a company has such lax policies, its open season.
Side note: if you have a fraudulent transaction on your credit card, don't call your credit card company and "dispute" a charge or ask for a "chargeback". Instead, call them and tell them you had a fraudulent transaction.
I had a clearly fraudulent charge on my Amex a few years ago (a Wal-Mart gift card was shipped to somewhere in Central California). I called Amex and asked to dispute the charge. Wal-Mart then provided Amex with the tracking info showing the package was signed for, and so they said that they had rendered the services paid for, and the case was closed in the merchant's favor.
It turns out that "fraud" is the magic word, not "dispute". I called Amex back and got into the fraud process instead, which of course fixed the issue.
In my country the "terminology" of credit card use isn't as evolved as it is in the US - we don't actually have well defined terms like "chargeback", "dispute" etc.
Which is what a chargeback is. In many cases if you let them know it was a case of identity theft, a different process is used and you are more likely to get your money back.
I suspect this because Amex is better staffed in this area.
Amex also directly provision merchant accounts for accepting Amex (separate to normal Visa/MC accounts) so they control both sides of the transaction.
This is reasoning by anecdote; your experiences are not a valid sample size with which to draw such general conclusions about the whole field. Look how many are saying the opposite is true, your experience is probably an outlier, not the norm.
In my experience, Amex is more likely to respond to a merchant presenting evidence that a chargeback is unwarranted. Visa/Mastercard essentially just say "tough luck," except in the case that a consumer has charged back by mistake.
Enraged I asked for the places and date/time stamps of transactions. I tracked the persons footsteps, some business owners allowed me to see security camera footage.
There she was, in her fast food uniform (the place I had ordered from earlier that day) in 3 different businesses at the exact same time of the debit card time stamps.
I took this information directly to the police were I was dismissed saying that my bank would do the investigation and not too worry about it. I went a head and spoke with the manager of the fast food joint as well. Morale of the story, the police don't do shit.
My theory is that police know that people pulled over in those areas are likely to be the responsible type who would pay for a ticket. And the person who stole and used your credit card is likely the type who would not pay tickets or fines but would end up having to spend time in jail. So, they target those who will pay tickets (a source of revenue) and ignore cases like yours that would result in no revenue.
Nobody gave a shit.
We asked our credit card processor, Stripe, what to do about fraudulent transactions. They told us that they had no way of notifying a bank about that kind of thing and to just refund it.
So now our policy is just to refund fraud and forget about it. It's a position we were forced in to. This means that the person whose credit card was stolen will continue to be abused and there really isn't anything we can do about it.
All very obviously fraudulent for example user in indonesia but cards from us
As a merchant who frequently gets bogus credit card order over the net I will confirm that nobody seems to particularly care about being notified that we feel it's highly probably that a credit card has been stolen. In other words there isn't a system in place even where a merchant who notices they have a stolen card being used can say "hey you should freeze this card or at least look into it".
IME, Amex is much better at flagging than the Mastercard I have.
It is not the case for all transactions but for most Swedish online transactions this has been the case for the past few years.
It is called something along the lines of 3-D secure/Verified by Visa
- additional verification code sent by SMS (France), see http://en.wikipedia.org/wiki/3-D_Secure
- bank provided card reader used with the card and pin code (Belgium)
I had Netflix and one day noticed I was billed twice on my credit card for Netflix service, one was OK but the other just appeared on my bill.
I used the online chat to talk to a Netflix rep who seemed unimpressed and not the least bit concerned (no frowny emoticon). I asked how a new charge I didn't authorize could appear on my credit card, she had no idea and just kept repeating the company line their system is unable to credit me, so I said but somehow it can magically take double the money? Nice.
Anyway, no apology, no concern so no Netflix.
You can forget about police doing anything to catch the criminals. The only good you get out of contacting police of such ID theft cases is that you can use the resulting paperwork to file claim with credit card company. Forget about police doing anything to actually go out to look for the criminals.
IMO, US police departments are firmly stuck in the mode of 'only-criminal-we-go-after-is-someone-with-a-gun-or-drug'.
It's been a while so the sequence of events is a bit fuzzy but basically I was a victim of ID theft a few years ago. A few checking/credit accounts opened using my name. 2 iPhones purchased using my name (not approved by me of course) at an official phone company store (meaning they were captured on security camera in the store). On Credit Report I pulled immediately after I learned what was happening, I saw my actual addresses and the criminals' addresses on the report. Interestingly the criminals were living in a 'dump' 1 year earlier but had since moved into a rental in a brand new condo complex. I mean a brand new, nice condo complex, also in San Jose area. I found out through Google Street View.
Now I had leads on their addresses and VIDEO FOOTAGE (in possession of the phone store in San Jose) of them existed. I was excited as I was headed to police station to file report. Well, what a disappointment. It seemed no one seemed interested in seeing the video footage. They just took my report (took me about 1+ hours in there). I got a generic confirmation letter from my police dept weeks later. I heard nothing from the police in San Jose. Weeks (or months later ?) I got a call from a US Postal Inspection Service investigator. He gave me names of 2 suspects and asked again if I knew them. I did not and am pretty sure they were the criminals. Thus the crime was being investigated by US Postal Inspection Service. So a potentially slam dunk case was being pushed around between 2 local police departments and a Federal agency. And the result was I was actually interviewed on the phone weeks/months after the crimes had occurred.
These pulps committed a crime that potentially cost someone else a few thousands bucks (cost of phone and fee and late fee), not to mention hours I had to spend to clean up the mess. But because the victim and criminals are in separate/distant jurisdictions, the police essentially did not do much on their own. They simply pushed the case off to a federal agency.
Had someone in my police department called San Jose police department to go look at a video foorage at a phone store and visit a local address up there, they could've caught the guys in a matter of hours or days.
Interestinly, months later I got a letter from landlord of the condo rental the criminals had rented. The landlord was demanding unpaid rent. The pulps had rented the complex using my name and when the fraudulent accounts were cut off and their money dried up, they fled without paying rent. The landlord's collector of course searched for my name and found the real 'me'.
The US police seems helpless with these crimes that cross multiple jurisdictions.
Of course, they also tracked down someone who stole a pair of sunglasses out of my car so my experience is likely atypical.
Why can't the money be followed?
If the NSA is such a powerhouse with billions of dollars of assets to track every electronic communication, why aren't they focusing their entire resources on people like the sellers?
Or is it like the TSA where they just hassle the completely innocent people at the airport for show while the real criminals take other paths.
The FBI would be investigating this, and they are probably actively following these transactions right now. But since they are a criminal investigation agency, they will be focused mostly on carefully collecting evidence, so that it can be used in trials to obtain convictions.
So: this exposes a gap in how the U.S. federal government approaches the Internet. The NSA is willing to react in real time to threats, but they don't care about crimes like carding. The FBI cares, but they seek to collect evidence, not react in real time.
The result is that when it comes to real-time reaction to cybercrime, companies are largely on their own. I'm sure Target is spending a good bit of money on cybercrime and cybersecurity consulting firms right now.
Because they didn't invest that kind of money to find the logs in a haystack that are eastern bloc cyber criminals. They are looking for a needle in a haystack dammit. A needle. (and possibly if some of their wives are cheating on them).
.su was the TLD of the Soviet Union.
http://www.cringely.com/2013/12/20/thoughts-grinch-stole-tar...
Second, his only actual argument is: "Someone probably made an out of process change to Target’s POS system and nobody noticed."
Sure, maybe. Or maybe someone subverted some other security system first. Who knows. Useless conjecture is just that.
Then he goes on about how the NSA should be fixing these issues. Okie dokie.
This is the same guy that doesn't understand how search engines work, and asked Eric Schmidt to manually fix his sister's website ranking in Google. I wouldn't take him as a useful source.
As to Target, there had to be a group. Somebody funding, someone inside, and then you've distribution networks for what effectively ends up as money laundering. At least that's the way I imagine it :)
Although that would be impressive, I'm sure you know you are full of shit, but other people don't.
Also Maksim Yastremsky (sp?) who the SS had Turkey work over for his FDE key because when they broke into his hotel room in Dubai couldn't extract info. That was from the 2007 big TJmax carding heist.
> Moscow voiced outrage over the arrest of a Russian national in the Dominican Republic and his swift transfer to a US jail without Russia’s consent or knowledge last month.