Not so very long ago, cash was the standard method of payment around the world. But then the credit card began its unstoppable rise. After all, paying for something on the Internet doesn't require photo ID, or a signature, just the credit card number. And e-commerce sites don't seem to care too much about whether these numbers are on the user's card, or on an illegal website.
Understandably, this has roused the interest of the criminal underground. Last year, Card Systems hit the headlines after the details of 40 million credit cards were stolen via a security loophole in the payment system. If you're on holiday, someone can use a card reader not only to process a transaction, but also to record all your credit card details for later use. The result: a nasty shock when you get home, and find charges have been made to your credit card that you were not responsible for. And you don't even have to be on holiday in one of the countries where credit card data theft is rife, as the arrest two years ago in Germany of an eight man group which copied tourists' credit card details in restaurants showed. Finally, spyware, phishing attacks and social engineering can also of course be used to steal data. The opportunities for data theft are numerous, although they vary in terms of complexity.
Normally, the people who steal the data are not the ones to use it. Instead, large numbers of credit card details are bundled together, and sold on for about a dollar a bundle. This sounds like a low price, but the vendor is less at risk than the buyer. Those who buy the data either use lots of cards to make lots of small purchases (in order to minimize the risk of being caught) or use a single card up to its limit. Credit card issuers often display leniency towards victims; however, there's no guarantee that a victim won't have to pay the charges run up on his/ her card.
The latest case
On 4th August 2006, while researching this topic, Kaspersky Lab came across a Russian website which included stolen credit card data. There were approximately 300 sets of data; some had clearly been on the site for a while, but on the day we discovered the site, 60 fresh sets of fresh data were added. Of course, compared to the coup of 40 million numbers last year, this is nothing. On the other hand, the credit card details on this site are being offered free of charge. And ultimately, it doesn't make any difference to a victim whether his/ her data is one entry in 300 or in 40 million.
In order to check the authenticity of the data, we called one of the German victims. On 15th May, the owner of the credit card noticed that about 10 euros had been charged to his card for a purchase which he hadn't made. On 26th May his credit card details were published on the site, and further purchases were made. He blocked his card, and Mastercard was obliging enough to reimburse him to help him get over the shock.
The victim explained that he did not normally use his credit card to make purchases online. But in May he had gone on holiday to the Czech Republic, where he'd used his card in restaurants and to buy petrol; it was clear from the date of the fraudulent purchases where the data had been stolen.
The format of other credit card details on the website showed that they clearly came from databases. It wasn't only Mastercard customers who were affected, but holders of Visa, American Express and Discovery cards too, including some platinum card holders.
One more interesting fact: a lot of the entries on the website were numbered with a six digit number. This makes it seem likely that the data on the website was only a small part of a far larger collection which contained more than 100,000 sets of data. A lot of these cards are only valid until 2008, so it's clear that the data is recent.
The current situation
In the meantime, we informed the authorities in Germany, the USA and Russia. The US office of Kaspersky Lab contacted Visa and Mastercard. As we wrote in our blog, communication with the authorities didn't go as smoothly either as we hoped, or as we had imagined it would.
A lot of questions remain unanswered. Where did the data come from? Did the members of the site steal it themselves? Did they really have access to large collections of credit card data? If so, then many more credit card holders were affected without knowing it.
Originally we planned to publish further details shortly after we published our blog. However, the authorities are still investigating, and we don't want to jeopardize the results of their investigation by revealing details prematurely This article therefore doesn't contain any screenshots.
How can you protect yourself?
Interesting as the background to this dubious site may be, credit card customers are probably more learning how they can protect themselves and prevent their data from ending up on similar sites.
The opportunities for abuse are numerous, and the list of steps you should take to protect yourself is equally long:
?Install antivirus software and a firewall on your computer
?Don't open attachments to emails from unknown sources ? even if the mail appears to come from eBay, your telephone provider, your bank etc, exercise caution.
?Always install patches to close vulnerabilities promptly
?Only use your credit card to make online purchases if the e-store offers a secure (SSL) connection. Make purchases from providers which are well known enough to want to avoid negative publicity (although this of course does not guarantee security 100%).
?Take care of your credit card. If someone manages to write down the details, you'll only find out about it when you get your next bill.
?Be careful on holiday ? travellers checks or cash are safer, particularly if you're in a country which is known for data theft. Your data can easily be copied at a petrol station, a restaurant or a shop without you having the slightest inkling.
?After returning from holiday, or after you've made an online purchase, check your credit card bills carefully ? people who use your data may only make small purchases in order not to give themselves away.
?If you lose your credit card, or think that your credit card details have been stolen, contact your card issuer immediately and have the card blocked.
Conclusion
Even after many years of e-commerce the relationship between credit cards and the Internet is an uneasy one. Whether credit card data is stolen over the Internet or the card details are published on a website is actually of secondary importance - the main issue is that credit card details can be stolen. This isn't the first such case, and it certainly won't be the last, at least for the foreseeable future.
After we blogged about this case, we received a lot of emails from victims whose credit cards seemed to have taken on a life of their own. This wasn't necessarily connected to the site which we found, but rather indicates that there's a lack of clarity about how the data could have been stolen in the first place.
As long as credit card issuers show tolerance towards their clients, and don't demand payment for fraudulent charges, the losses which the cardholder suffers will be limited. However, these losses will impact on the cost of service, and these costs will therefore finally be borne by customers. Even though stolen cards can be blocked, it's not much consolation for the card holder who knows that his/ her home address had been published on a resource visited by criminals. Blocking a card is merely a temporary solution; both for the card holder and for the card issuer.
As stated above, Kaspersky Lab has forwarded all the relevant information to the authorities, so the case is now in their hands. However, it'll take days, if not weeks, before this story is concluded: we'll keep you posted on the developments.
Source:
Kaspersky Lab
Definition A La Carte
Here is a sampling of the extensively diverse Indonesian travel menu.
Sumatra
Sitting on the equator, Indonesia's largest province is covered with tropical rainforests which is home to a rich collection of flora and fauna ecosystem. The island boasts of several reservation areas including Mount Leuser National Park, home of the endangered Sumatra Orang-utan and Berbak Wildlife Reserve which accommodates the largest tiger population in Indonesia.
Bali
Its serene panorama, both on land and underwater, simply fills the senses with the beauty of nature and the wonders it offers to man. Aside from the breathtaking beaches, Bali also takes pride of Bali Barat National park, home of a number of bird species declared as among the rarest and most beautiful in the world.
Borobudur Temple
Located on a hilltop in Central Java, Borobudur Temple is one of the world's most celebrated Buddhist temples. Dated back to the 9th century A.D., the temple was discovered in 1984 under thick forest foliage. After a successful restoration, the temple showed panels carved in stone that tells of the life of Buddha and the tenets of Buddhism.
Komodo National Park
By the name alone, it obviously is world-famous Komodo dragon's only home on earth. It is one of the oldest and rarest reptile specie that has survived several earth eras. The largest reptile, growing up to three meters or more, is actually a monitor lizard that hunts and scavenges around the barren lands of Komodo Island.
Bromo-Tengger National Park
Bromo-Tenger was already a buzzling community long before the concept of Indonesia was conceived. It is located in Mount Semeru where thousands of Hindus flock for annual pilgrimage in honor of the god that looks after the mystical place which is composed of volcanoes covered by thick forests. Most of these volcanoes are still active lead by the notorious Semeru volcano that records an eruption every eight minutes.
Bunaken Marine Park
With marine biodiversity comparable to the Great Barrier Reef of Australia, Bunaken Marine Park is a heavenly refuge for avid divers and snorkelers. Both amateur and pro underwater explorers will surely be mesmerized by the rich collection of colorful corals and reefs that are homes to an equally rich assembly of fish and marine animal species.
Robert Thomson has sinced written about articles on various topics from Personal Desktop, Finances and Pets. For accommodation in Indonesia please visit: . For other options:. Robert Thomson's top article generates over 450000 views. to your Favourites.
Bicycle Carrier For Car Deciding beforehand which type of wheelchair carrier you need will help you to choose the one that will optimize your traveling time