Stolen Credit Card Details Cost £1 Online

UK credit card details are on sale for as little £1 each online as fears rise over the security of personal data in the wake of the TalkTalk cyber-attack.

More than 600,000 individuals had their personal details stolen from UK companies in 2014, according to the Financial Times, underlining the scale of online crime in this country. It is likely that some of that data will have ended up on a website used by criminals wanting to buy high-end UK credit card data.

Visa and MasterCard details stolen on recently were offered to the Guardian the following day - provided payment was made in the crypto-currency bitcoin - on a website which is registered in Russia but run in English.
The site did not reveal where the details were harvested from, but the ownership of the cards was clear. One credit card was registered to a person in Craigavon in north County Armagh; another belonged to a resident of Chelmsford, Essex, who lost their platinum Visa card earlier this week. Platinum cards are particularly attractive to fraudsters because of their high credit limit. Scores more card details, registered to addresses up and down the country, from Aberdeenshire to Devon, were openly for sale on the site.

The example of the Russian-registered site is striking because it is on the “surface” web, and easily available to conventional Internet users. It has a high-end design and layout, offers customer support and promises an 80% success rate for the buyers of stolen cards. It sits at the luxury end of the identity theft market, and charges accordingly – it wanted $72 (£47) for each card sold to us.

To bulk buy stolen data at lower prices, however, fraudsters head to the dark web. This can be accessed via the Tor browser, rather than conventional browsers used by the vast majority of users. It bounces a connection through multiple encrypted relays before it hits its destination. This obscures where the site’s server is located, allowing would-be identity thieves to connect to hidden services, and sites not accessible to non-Tor users.

Searching through Tor, it is possible to access a site which will sell 100 credit cards (with the CVV2 digits – the three numbers on the reverse of the card) for just $150 (£98), around £1 per card. The site also sells PayPal accounts at $100 for 100, while other hidden services will offer €1,250 of counterfeited notes for €500. Free shipping is included.

Buying the stolen information is just the first step in a process that criminals use to convert digital data bought online into hard cash. The credit cards are used to load money onto easily obtained pre-paid debit cards. These are payment cards that function similar to credit cards, and can be used to shop online, but can be opened without the sort of checks wanted by banks when opening a current account.

These pre-paid debit cards are used to buy online gift cards. In turn, these gift cards are used to buy high-value electronics, such as iPhones or games consoles, which are sold at a discount – an iPhone 6S for $430 or an Xbox One for $240. That cash goes in the pocket. But how do these dark websites get the data? A significant source of stolen information, particularly in the US, is old-fashioned card-skimming: a compromised terminal or company employee on the take, who steals the details of a card in the process of completing a transaction.

Just as common is the 21st-century equivalent: malware. This is the catch-all term for malevolent software that infects an individual’s computer to monitor communications for confidential information such as banking passwords, credit card details and social media logins. The data is uploaded to a central server where it is sold on or used to further spread the malware.
The Gameover Zeus malware, disrupted by a joint UK-US operation in June 2014, was one such attack. This acted as a form of “ransomware”, encrypting the infected computer and demanding payment in bitcoin to release the data.

The third major source of data for sale is large-scale hacks, of the type that was flagged by telecoms operator TalkTalk on 23 October. Sometimes the stolen information can be used directly, especially where the company has irresponsibly stored credit card data or passwords on their servers in plaintext; or it may be used as the first step in stealing someone’s identity, where information from two or more hacks is linked to build a profile that can be used to apply for bank accounts or credit cards.

Security experts call the organised criminal hacks “advanced persistent threats”. But the attack on TalkTalk has left researchers bemused. A 15-year-old boy from Northern Ireland is on police bail in connection with the cyber-attack, while on Friday a 16-year-old boy was arrested in London.

TalkTalk appears to have been the victim of a relatively amateur and opportunistic hack, according to experts. The company’s chief executive, Dido Harding, said the perpetrator exploited a “sequential injection” attack. Security researchers, realising she meant to say “SQL injection” – a common form of attack in which a hacker tricks the website into releasing information from a database – had a field day.

“It’s not the lowest-hanging fruit of all,” said David Enn, a researcher at information security firm Kaspersky. “But certainly in terms of attacking core infrastructure of the business, we’re not looking at a concerted, targeted attack. What you’re talking about here is like managing to sneak through the security barrier just by slipstreaming an employee.”
 
TalkTalk declined to discuss its defences in detail, given the ongoing police investigation, but said it continually invested in improving its systems, and constantly monitored and scanned its network to detect any weaknesses.

“We defend against all manner of attacks on a day by day basis,” a statement said. “Each day we have to block over 170m scamming emails to our customers, and we block over 1m nuisance calls to our customers each day.

“It is a constantly evolving fight against cybercrime and individual companies on their own can’t tackle this problem.”

Guardian

 

« UK Forced To Backtrack on Internet ‘snooping’
RBS Says Most Scam Victims Recover Nothing »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Directory of Cyber Security Suppliers

Directory of Cyber Security Suppliers

Our Supplier Directory lists 7,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

Conscio Technologies

Conscio Technologies

Conscio Technologies is a specialist in IT security awareness. Our solutions allow you to easily manage innovative online IT awareness campaigns.

QASymphony

QASymphony

QASymphony software testing and QA tools help companies create better software by improving speed, efficiency and collaboration during the testing lifecycle.

UZCERT

UZCERT

UZCERT is the national Computer Emergency Response Team for Uzbekistan.

ANSI National Accreditation Board (ANAB)

ANSI National Accreditation Board (ANAB)

ANAB is the largest accreditation body in North America. The directory of members provides details of organisations offering certification services for cybersecurity related standards.

Startup Wise Guys

Startup Wise Guys

Startup Wise Guys is a mentorship-driven accelerator program for early stage B2B SaaS, Fintech, Cybersecurity & Defense AI startups.

Cambridge Cybercrime Centre

Cambridge Cybercrime Centre

The Cambridge Cybercrime Centre is a multi-disciplinary initiative combining expertise from the Department of Computer Science and Technology, Institute of Criminology and Faculty of Law.

Gula Tech Adventures

Gula Tech Adventures

Gula Tech Adventures invests in companies and nonprofits that help close the gap in needed technology and workforce to defend the country in cyberspace.

SIA Group

SIA Group

SIA Group, an Indra company, combines Consulting, Systems Integration and Managed Services in four specialized business areas: Information Security, Storage, IT Management and IT Mobility.

ramsac

ramsac

ramsac provide secure, resilient IT management, cybersecurity, 24 hour support and IT strategy to businesses in London and the South East.

Cysurance

Cysurance

Cysurance is a next-generation risk mitigation company that insures, warranties and certifies security solutions.

WPScan

WPScan

With WPScan, you'll be the first to know about vulnerabilities affecting your WordPress installation, plugins, and themes.

NexusTek

NexusTek

NexusTek is a managed IT services provider with a comprehensive portfolio comprised of end-user services, cloud, infrastructure, cyber security, and IT consulting.

Evolver

Evolver

Evolver delivers technology services and solutions that improve security, promote innovation, and maximize operational efficiency in support of government and commercial customers.

Klarytee

Klarytee

Protect your data wherever it goes. Klarytee is a SaaS platform that builds security into sensitive content to enable granular control in AI, public cloud and SaaS.

Xeol

Xeol

Software free of vulnerabilities, built and distributed by trusted entities. Our mission is to help customers secure their software from code to deploy.

Chorus

Chorus

Chorus are a leading Managed Security Service Provider (MSSP), and member of the Microsoft Intelligent Security Association (MISA), with three Microsoft Advanced Specialisations in security.