Stolen Credit Card Details Cost £1 Online

UK credit card details are on sale for as little £1 each online as fears rise over the security of personal data in the wake of the TalkTalk cyber-attack.

More than 600,000 individuals had their personal details stolen from UK companies in 2014, according to the Financial Times, underlining the scale of online crime in this country. It is likely that some of that data will have ended up on a website used by criminals wanting to buy high-end UK credit card data.

Visa and MasterCard details stolen on recently were offered to the Guardian the following day - provided payment was made in the crypto-currency bitcoin - on a website which is registered in Russia but run in English.
The site did not reveal where the details were harvested from, but the ownership of the cards was clear. One credit card was registered to a person in Craigavon in north County Armagh; another belonged to a resident of Chelmsford, Essex, who lost their platinum Visa card earlier this week. Platinum cards are particularly attractive to fraudsters because of their high credit limit. Scores more card details, registered to addresses up and down the country, from Aberdeenshire to Devon, were openly for sale on the site.

The example of the Russian-registered site is striking because it is on the “surface” web, and easily available to conventional Internet users. It has a high-end design and layout, offers customer support and promises an 80% success rate for the buyers of stolen cards. It sits at the luxury end of the identity theft market, and charges accordingly – it wanted $72 (£47) for each card sold to us.

To bulk buy stolen data at lower prices, however, fraudsters head to the dark web. This can be accessed via the Tor browser, rather than conventional browsers used by the vast majority of users. It bounces a connection through multiple encrypted relays before it hits its destination. This obscures where the site’s server is located, allowing would-be identity thieves to connect to hidden services, and sites not accessible to non-Tor users.

Searching through Tor, it is possible to access a site which will sell 100 credit cards (with the CVV2 digits – the three numbers on the reverse of the card) for just $150 (£98), around £1 per card. The site also sells PayPal accounts at $100 for 100, while other hidden services will offer €1,250 of counterfeited notes for €500. Free shipping is included.

Buying the stolen information is just the first step in a process that criminals use to convert digital data bought online into hard cash. The credit cards are used to load money onto easily obtained pre-paid debit cards. These are payment cards that function similar to credit cards, and can be used to shop online, but can be opened without the sort of checks wanted by banks when opening a current account.

These pre-paid debit cards are used to buy online gift cards. In turn, these gift cards are used to buy high-value electronics, such as iPhones or games consoles, which are sold at a discount – an iPhone 6S for $430 or an Xbox One for $240. That cash goes in the pocket. But how do these dark websites get the data? A significant source of stolen information, particularly in the US, is old-fashioned card-skimming: a compromised terminal or company employee on the take, who steals the details of a card in the process of completing a transaction.

Just as common is the 21st-century equivalent: malware. This is the catch-all term for malevolent software that infects an individual’s computer to monitor communications for confidential information such as banking passwords, credit card details and social media logins. The data is uploaded to a central server where it is sold on or used to further spread the malware.
The Gameover Zeus malware, disrupted by a joint UK-US operation in June 2014, was one such attack. This acted as a form of “ransomware”, encrypting the infected computer and demanding payment in bitcoin to release the data.

The third major source of data for sale is large-scale hacks, of the type that was flagged by telecoms operator TalkTalk on 23 October. Sometimes the stolen information can be used directly, especially where the company has irresponsibly stored credit card data or passwords on their servers in plaintext; or it may be used as the first step in stealing someone’s identity, where information from two or more hacks is linked to build a profile that can be used to apply for bank accounts or credit cards.

Security experts call the organised criminal hacks “advanced persistent threats”. But the attack on TalkTalk has left researchers bemused. A 15-year-old boy from Northern Ireland is on police bail in connection with the cyber-attack, while on Friday a 16-year-old boy was arrested in London.

TalkTalk appears to have been the victim of a relatively amateur and opportunistic hack, according to experts. The company’s chief executive, Dido Harding, said the perpetrator exploited a “sequential injection” attack. Security researchers, realising she meant to say “SQL injection” – a common form of attack in which a hacker tricks the website into releasing information from a database – had a field day.

“It’s not the lowest-hanging fruit of all,” said David Enn, a researcher at information security firm Kaspersky. “But certainly in terms of attacking core infrastructure of the business, we’re not looking at a concerted, targeted attack. What you’re talking about here is like managing to sneak through the security barrier just by slipstreaming an employee.”
 
TalkTalk declined to discuss its defences in detail, given the ongoing police investigation, but said it continually invested in improving its systems, and constantly monitored and scanned its network to detect any weaknesses.

“We defend against all manner of attacks on a day by day basis,” a statement said. “Each day we have to block over 170m scamming emails to our customers, and we block over 1m nuisance calls to our customers each day.

“It is a constantly evolving fight against cybercrime and individual companies on their own can’t tackle this problem.”

Guardian

 

« UK Forced To Backtrack on Internet ‘snooping’
RBS Says Most Scam Victims Recover Nothing »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

Snort

Snort

Snort is an open source intrusion prevention system capable of real-time traffic analysis and packet logging.

Allianz Commercial

Allianz Commercial

Allianz Commercial is the center of expertise and global line of Allianz Group for insuring mid-sized businesses, large enterprises and specialist risks.

CyberSource

CyberSource

CyberSource provides online payment and fraud management services for medium and large-sized merchants.

Global Learning Systems (GLS)

Global Learning Systems (GLS)

Global Learning Systems provides security awareness and compliance training programs for employees that effectively promote behavior change and protect your organization.

Shift Technology

Shift Technology

Shift Technology provides insurance companies with an innovative SaaS solution to improve and scale fraud detection.

State e-Government Agency (SEGA) - Bulgaria

State e-Government Agency (SEGA) - Bulgaria

The State e-Government Agency (SEGA) is responsible for matters relating to electronic governance in Bulgaria.

Unit21

Unit21

Unit21 helps protect businesses against adversaries through a simple API and dashboard for detecting and managing money laundering, fraud, and other sophisticated risks across multiple industries.

Kratos Defense & Security Solutions

Kratos Defense & Security Solutions

The Kratos Space, Training, and Cybersecurity division addresses key cybersecurity challenges, including cloud security, continuous monitoring, IT security, and risk management.

Finnish Security & Intelligence Service (SUPO)

Finnish Security & Intelligence Service (SUPO)

The Finnish Security and Intelligence Service is a government agency tasked with combating serious threats to national security in Finland.

IoTeX

IoTeX

Building the connected world. IoTeX is a fast, secure, and decentralized platform that connects real world devices/data to the blockchain.

Maxxsure

Maxxsure

Maxxsure provides a platform for executive management, leveraging proprietary technology that identifies, measures, and scores a company’s cyber risks.

CYGNVS

CYGNVS

CYGNVS is a guided cyber crisis response platform providing anytime, anyplace access. A SaaS platform for cyber crisis management – a safe way to connect and control your response.

Lakera

Lakera

Lakera empowers developers and organizations to build GenAI applications without worrying about AI security risks.

MARS Suite

MARS Suite

MARS Suite is your all-in-one solution for cyber protection & compliance. Cybersecurity and risk management is what we do best. And we’re making it simple and easy.

Clumio

Clumio

Clumio provides autonomous backup and recovery for critical cloud data.

CrashPlan

CrashPlan

CrashPlan provides peace of mind through secure, scalable, and straightforward endpoint data backup.