Peek Inside a Professional Carding Shop
krebsonsecurity.com
krebsonsecurity.com
It is funny how this business has not changed since 1998. The communication channels changed, but the ideas and market is still the same. My first introduction to this was with the Windows RPC remote exploit vulnerabilities. I setup some honeypots to determine what the botnets were up to (most were manual B/C class scans at that time, the good old days before decentralized command). I ended up following the trail of controllers up to a random efnet IRC chatroom and finally to a more private area. That's where they sold/traded data from the botnets. This was prior to the 'rent a botnet to DDoS' era.
Back then, credit cards without CVV2s (from Windows IIS Servers exploited with that long string bug leaking out plain text documents) were worth about 50 cents a piece. CVV2 brought it up to around $2-3 for US, $4-6 for UK/CA. Address information was around $15. It seems the market has deflated a lot, the credit cards are probably from targeted companies rather than scripted botnets looking for vulnerable boxes, and the data can just be bought from a website rather than having to get a third party to moderate the exchange.
Once again,the comments reminded me the most of that community. Someone mentioned about entering CC info on a CC theft site. There used to be a RTF document exploit where you could execute something or another from them, the dump sellers would infect their dump files (RTF docs) and steal the client's data. These communities are cutthroat.
(Just kidding, I know it's obviously because they aren't using a broken, insecure payment mechanism for transactions, like our credit card system.)
I feel like that's the point you were making with that last sentence, but I missed the sarcasm until typing all the above out.
http://validshop.su/usercp/auth/login
That's one of the biggest CVV websites, they sell the CC#/CVV/FirstName/LastName/Address
These websites are not hard to find, just have a look on a few 'underground' forums and you'll see the advertisements.
Krebs gets invited in, vouched for, and shown new forums by that last group.
I even have two completely separate checking accounts, at two different banks. One is only used at ATMs, and the other is only used to pay my CC bill. Neither are ever used online or at any physical merchant.
Credit cards use the bank's money on credit. Most credit card users are only liable for $50 in damages.
Someone spent $2,000 at Comcast and Neiman Marcus on my card in one night. I reported it the following day and it was reversed and I was given a new card the same day.
I would love more information from a banker on how the fraud disputes are won. Sometimes the merchant pays, sometimes the bank pays, sometimes it split in percentages. I know it has to do with how the merchant processed the payment or if a pin number was used for the transaction.
Credit card fraud recovery is mandated by the federal government.
The primary difference is in the case of fraud on a debit card, you don't have access to the stolen funds until your financial institution issues a provisional credit. (They have a short statutory time frame to do this.)
I suppose you have to be a bit more careful about these things with how easy the internet makes it to steal cards and sell the info to somebody else who can exploit the stolen card info with less risk.
What you do gotta look out for is forgetting to add money in, but if you get a bank that is good about not allowing overdrafts to occur you can mitigate overdraft fees.
Anyway, yeah you might be safer with a credit card, but then you have a credit card.
This shouldn't be seen as a bad thing. Like anything else, a credit card is just a tool. It can be used productively, or abused.
A conversation with a banker revealed that the common trick here is for thieves to attach cameras to ATMs to grab details, and then build mimic cards to drain accounts. The bank was pretty cooperative in processing my claim, and said they should have the money back to me in about 45-180 days. So, that's kinda lucky.
I'm going to be extra observant at ATMs from now on though.
The branch manager showed me photos of the skimmer gear and the police report. It was made to look like part of the ATM housing. She said over 200 customers were ripped off in one weekend.
Even though they knew it was their own machine that was compromised, it still took almost a month and many hours of phone calls and letter-writing to get my money back.
How are people capturing the numbers, transferring them, and (I assume) creating fake cards to use in-store so fast?
I've never used this card in an ATM so it must be from a store that swiped my card.
Here's my questions though, how did the fraudster know my pin number to be able to use the cloned credit card in an ATM?
I still don't know how they got my pin. I can't imagine anyone looking at my pin in a restaurant. It seems like such a hard and non-scalable way to do this kind of thing.
Did people think they could buy Big Mac Hamburgers online with bitcoins and get delivery over email?
Even so, just because you can see your card doesn't mean someone cannot copy it. They could even have a modified device that automatically log all cards while also performing transactions. In such a scenario you would see nothing out of the ordinary.
Though I normally pay cash in restaurants I don't trust absolutely.
I try to use my CC online as little as possible and in the real world only when I have the card in view at all times and the pin verification terminal is under my control while I enter the pin, and crucially, contains the card (so I won't use it if the terminal is in one spot and the card in another).
I never use swipe.