Showing posts with label payment card fraud. Show all posts
Showing posts with label payment card fraud. Show all posts

Wednesday, February 06, 2019

Huddle House Reports Point of Sale Hacked Since August 2017

If you had a meal at Huddle House and used a payment card -- you might want to give the issuing financial institution a call (or review your account online) and make sure your financial health wasn't compromised! Huddle House announced that the compromise occurred from the beginning of August 2017 until "present."

It always amazes me how long compromises go on without being detected. In this case, it was well in excess of a year!


Huddle House is a casual dining and fast food chain that operates in the southeastern United States. On 02/01/2019, they announced that their point of sale system had been hacked on the main page of their website. 


Huddle House reported that the following personal details were compromised:


"Based on the facts known to Huddle House at this time, the malware was designed to collect certain payment card information from the magnetic stripe, including cardholder name, credit/debit card number, expiration date, cardholder verification value, and service code."


The page also details all the resources available to protect yourself. 


Please note that some people opt for "paid services" to protect their financial resources, but you can also do it yourself for free. 


Free credit reports are available at AnnualCreditReport.Com and the Federal Trade Commission has great information on how to deal with any issue that arises from using your card at Huddle House.


In the United States, billions of dollars of payment card fraud are incurred by customers, banks, and merchants a year. The biggest losers are the merchants, but we can assume that we are all paying for it when these losses are passed down to the consumer via higher prices and fees.


Please note that there are varying estimates of the true cost of fraud. Based on years of personal experience, I have always found that large amounts of fraud loss are buried as "bad debt" because no one (normally a Collections Department or Fraud Department) spent the time to investigate the true cause of the loss. 


The sad thing is that when this happens, fraud losses tend to go up because no one is effectively mitigating the root cause of how the money is being stolen. 


Sunday, June 29, 2008

Wards will now start notifying customers their information was stolen in December

The Associated Press announced on Friday that old time retailer Montgomery Ward is the latest victim of a data breach, where at least 51,000 records were compromised. The unfortunate problem now is they failed to notify the victims, which is the law in 44 States.

Since Montgomery Ward declared bankruptcy in 2001 this announcement might sound confusing, but the company was resurrected in 2004 under the name, Direct Marketing Services Incorporated. Direct Market Services sells merchandise under the names Wards.com, SearsHomeCenter.com, SearsShowplace.com, SearsRoomforKids.com (and two more) online.

Allegedly, hackers gained access by going through another Direct Marketing Services site, HomeVisions.com.

When they discovered the hack in December, they did notify their payment processor, Visa and Mastercard, but failed to notify any individual customers. Of course, they now plan to do so after being asked about it by the Associated Press.

The hat tip in this instance goes to CardCops, which a group of cyber sleuths who track stolen payment card data in underground carder forums for financial institutions. CardsCops spotted a group of 200,000 card numbers for sale (including CVC data) on one of the forums (chatrooms) they were monitoring. After tracing some of these cards to their owners, they discovered that they were had one thing in common (Wards).

At this point, it is unclear on whether the official estimate of 51,000 missing records is correct, or the hackers misrepresented the number of cards available in their underground forum.

When asked for some commentary, Visa declined to comment, MasterCard stated they warned the issuing banks to watch for suspicious activity and Discover stated they issued new cards.

Wards is not alone in not notifying their customers, or the public promptly when a data breach occurs. Recently lamented about this in a post suggesting we are a long way from full disclosure in data breaches.

Even without all the known data breaches, there are many that are never discovered. Besides that, information is stolen all the time on a smaller scale by dishonest employees, phishing and (despite all the shredders) from the trash.

The sad truth is from the criminal perspective, stolen information that hasn't been detected is worth more than information that is known to be "hot."

If you would like to see more information on the known data breaches, the DLDOS database at Attrition.org is a good resource. PogoWasRight is also another place that covers the privacy concerns arising from this problem, which faces us all.

Sunday, June 15, 2008

Credit Card fraud used to fund Terrorist Organization

Here is an example of cyber crime being used to fund terrorism. Fortunately, the person behind this is now behind bars.

The Sri Lanka Ministry of Defence website reported:

The mastermind behind the international credit card fraud for funding the LTTE terrorist organization has been arrested by the Special Task Force (STF) personnel while conducting a search operation in the Wellawatta area on Friday, June 13.

The suspect Anandan, alias Neshanadan Muruganandan, was in a super luxury apartment in Wellawatta at the time he was arrested by the special police team, sources said. He had a large number of Personal Identification Numbers (PIN) and bank receipts issued by both local and foreign banks, amounting to a massive sum of money, over Rs. 100 million, in his possession when he was arrested.

This isn't the first time a tie between payment (credit/debit) card fraud and funding terrorism has been suggested. In the past, it's been widely reported that Al Qaeda training manuals teach their minions to use credit card fraud as a way to survive in foreign lands.

There has also been speculation that organized crime and terrorists mingle in the underground economy when it suits their needs. In another story, also found on Sri Lanka's Ministry of Defence site, it mentions that 130,000 passports were stolen and that some of them were provided to the highest bidder (Al Qaeda).

Also mentioned in the interesting story is other ways this terrorist group, the Tamil Tigers, obtain their funding.

While I doubt organized criminals, and or terrorists are going to admit they are taking advantage of stolen personal and financial information in public, it could be a bigger problem than we realize (?).

Here in the West, Suad Leija and her husband have been trying to get this message out to everyone on their site (Paper Weapons). If you are interested in understanding how paper (and sometimes plastic) weapons might be used by people with twisted political objectives, I highly recommend visiting their site.

Saturday, March 29, 2008

How did hackers plant malware at Hannaford Bros. and steal 4.2 million payment card numbers?

Hannford Brothers, the latest retailer to be compromised in a large scale data breach is reporting that hackers using malware breached their systems.

The next million dollar question (literally) is how was the malware (sometimes referred to as crimeware) dropped on their system? A lot of people are looking at this carefully because the company had been certified as meeting PCI (Payment Card Industry) data protection standards.

Ross Kerber at the Boston Globe, who gets the hat tip for breaking this latest development in the story wrote:

Data security specialists say the new details show how hackers have grown more adept at penetrating weak links in the systems that connect merchants and banks. In previous breaches, such as the record-setting intrusion at TJX Cos. of Framingham, where as many as 100 million card numbers were compromised, hackers took advantage of merchants who stored customer names and card data - sometimes in violation of payment industry standards - at central locations in their computer networks.

In contrast, Hannaford says it did not store customer information. The hackers who struck Hannaford mined a stream of data that the merchant and banks were not responsible for protecting under industry rules, industry specialists said.
Because hackers, criminals and misfits rarely give up their latest hacks, we'll have to be content with speculation from the experts.

Jaikumar Vijayan at ComputerWorld was able to get some expert speculation from "Mike Paquette, chief strategy officer at Top Layer Networks, a vendor of intrusion-prevention systems in Westboro, Mass." Bill Brenner at SearchSecurity.com wrote about increasing speculation that a dishonest insider planted the malware on Hannaford's network.

The insider theory intrigues me because it seems that most security breaches can be traced to a social cause. A dishonest human --who has been given access to a system -- can defeat a lot (most) computer security.

Going further into all the speculation has come about from the Hannaford announcement, I decided to see what the blogosphere had to say.

Securosis.com gives a lot of interesting perspective in their post, Picking Apart The Hannaford Breach- What Might Have Happened .

The post points out some interesting thoughts, such as that credit card numbers are useless without names (Hannaford claims no names, or social security numbers were stolen) and that the breach was most likely discovered at financial instiutions when customers complained about fraudulent transactions on their cards.

rmogull summed up his "admitted" speculation with:
In conclusion, it looks like some sort of a network breach (which could be anything from phishing/malware to compromise from a retail location to a full network hack). A sniffer was possibly installed, since it seems they don’t keep credit card information (again, assuming statements are true). The fraud was detected by the banks or credit card companies, then it took a little under two weeks to contain. Not great, and indicative of either a little sophistication on the attacker’s part, or a lack of sophistication on Hannaford’s part.
There are also some interesting comments with more speculation at the bottom of the post. From what I can gather a lot IT types read this blog.

In the end, as long as there is lack of transparency in data breaches, the best anyone can do is speculate. The reasons for a lack of transparency in data breaches are a mile long, encompassing everything from protecting ongoing investigative efforts to avoiding the financial pitfalls of all the litigation that arises after a data breach.

Of course, in more simple terms, it might also mean that no one is really sure?

Given that, I wonder if anyone can be really sure that their personal information is safe? Your guess is probably as good as mine!

Previous posts on this blog about the Hannaford Data Breach:

Security vendor removes Hannaford as a client on their site after data breach is revealed!

Hannaford Brothers data breach might reveal current security standards are outdated

Thursday, February 14, 2008

EBT cards probably have done little to reduce benefits (welfare) fraud!

Several years ago, one of the reasons plastic electronic benefit transfer (EBT) cards were introduced was to reduce benefits (welfare) fraud.

Apparently, criminals preying on government entitlement systems have figured out how to keep right on scamming the system using this form of "plastic."

Dan Cortex of the Free Detroit Press reports:

An intricately coordinated raid 18 months in the making resulted in the arrests Tuesday of more than two dozen business owners and employees involved in a fraud that costs the state about $55 million annually.

At least 25 people were arrested when about 200 state, federal and local officials descended on the stores, mostly in Dearborn and Detroit.
Interestingly enough, the manner in which this was accomplished wasn't very sophisticated:

Instead of using the cards to buy food, State Police said some card owners collaborated with store owners to trade them in for cash at the stores -- often at half the value of the cards. The stores, in turn, collected the full amount on the debit cards from the state.
Before EBT cards the same thing used to occur using the paper food stamps issued to government assistance recipients. With the use of electronic payment systems, converting the benefits to cash is probably less labor intensive than it used to be for the criminals involved in this activity.

The article also mentions that bank accounts and passports were seized. Do passports being seized mean that some of these people aren't even citizens?

Because of this, I decided to dig a little further. I was able to find a little more information on the Michigan Attorney General's site.

Here is what they are being charged with:

The defendants are charged with a felony violation of the food stamp act for which the maximum penalties are 10 years imprisonment and/or $250,000 in penalties. In addition, the stores and its owners and employees are charged with conducting a continuing criminal enterprise (punishable by up to 20 years imprisonment and/or $100,000 and criminal forfeiture of proceeds), conspiracy (up to 5 years imprisonment and/or $10,000 fine), electronic benefit transfer (EBT) card fraud (4 years imprisonment and/or $4,000 fine), and money laundering (10 year imprisonment and/or $100,000 in fines).

Considering how easily this was done, I'm guessing that it might be happening in other places, also. Maybe other States should look into this matter like the great State of Michigan has? Given how easily this was accomplished, I doubt Michigan is the only place with a problem.

One thing is for certain - I don't think plastic has stopped very much of this particular type of fraud. The true victims in this are the people probably going hungry at the expense of these criminals. In reality, they are doing nothing more than stealing food from the mouths of children!

The insane thing is how did we ever think that electronic payment cards would reduce fraud? All anyone would have had to do is take a look at how easily debit and credit cards are compromised.

Also not mentioned in the mainstream media were the names of the alleged defendants. Given that passports were seized, I'm guessing that some of the alleged defendants might be considered a flight risk:

Citgo
8351 Woodward Detroit, Michigan

Nabil Shamel, owner

Jamal Chami, employee

Waad Fawazi, employee

Livernois Gasoline
7645 Livernois Detroit, Michigan


Hafaid Musleh-Mohmood Alkahif, owner

Abdul Fattah-Mohmood Alkahif, employee

Dheyab M. Alquhaif, employee

Ammar Mahmood Gobah, employee

Mustafa Mohamen-Ahmed Alqohaif, employee

Yousef Mohamed-Ahmed Alqohaif, employee

U&I Petro
8820 Wyoming Detroit, Michigan

Saleh Algathaithi, owner

Saif Ahmed Alghathie, employee

Hassan Ali Hussein, employee


C&M Mini Mart
18420 James Couzens Detroit, Michigan

Abdo Mahfouz, owner

Ali Abdo Mahfouz, employee

Tarek Moshen Baderddine, employee


Rowan Party Store
7000 Rowan
Detroit, Michigan


Saeb Abdul-Ghani Abdul-Ghani, owner

Joseph Soliman Elrubi, employee

Maher Diab, employee


Big Al's Marathon
3910 Grand River Detroit, Michigan


Hussien Kamel Beydoun, owner

Ali Hussein Beydoun, employee

Van Dyke Petro
19030 Van Dyke Detroit, Michigan

Taha Ahmad Dika, owner

Nizar Ali Nazha, employee

Michael Maher, employee

Bassel Ibrahim-El-Sayed-Sleim Hachem, employee

Schaefer & Puritan
15901 Schaefer Detroit, Michigan

Mr. and Mrs. Adel Mohamad Kobeissi, owner

Khaled Abid Al-Bonijim, employee

Moahamad A. Berro, employee

Detroit Free Press article, here.

Press release from the Michigan Attorney General's Office, here.

Article from 1998 (WRAL.com) about how EBT cards reduce fraud, here.

Saturday, November 10, 2007

Visa's big break to TJX on security standards during their data breach!

The TJX data breach -- which in case you haven't heard just doubled it's estimate of records compromised from 45 to 90 million -- has caused a lot of finger pointing between the financial and retail sectors.

Of course, this was revealed in court filings (like the revelation below) and I'll be surprised if anyone is willing to answer any questions about it.

The latest is that Visa knew that TJX had "extensive security problems," but chose to let them off the hook to become PCI compliant until 2009.

Evan Schuman of EWeek reports:

Credit card company Visa knew in late 2005 of the extensive security problems at TJX, but decided to give the retailer permission to remain non-compliant through Dec. 31, 2008, according to documents filed in federal court on Nov. 8.

The Dec. 29, 2005, letter from Joseph Majka, a fraud control vice president for Visa, was written months after cyber-thieves had already secretly infiltrated TJX's systems, starting the work that would ultimately become the worst data breach in credit card history.

Ironically -- while hackers were happily stealing a lot of PEOPLE's personal and financial information -- Visa wrote TJX telling them they would be holding off from fining them as long as they were diligent in fixing the problem.

In 2007, Visa fined one of TJX's banks before the deadline had expired.

PCI compliance standards are enforced by the payment card industry themselves. All that seems to be coming out of the largest data breach in history is a lot of finger pointing and litigation, which like fines, are driven by a financial incentive.

I hate to say it, but neither side of the fence wants to stop using plastic. They both are making billions of dollars in the process.

Perhaps -- if an entity with no financial stake in all this dictated the standards --the people having their information stolen by criminals would be a LOT better off.

The question is when are people (customers) going to come first?

eWeek story, here.

Saturday, November 03, 2007

Does anyone really know how much information was lost by TJX?

About a week ago, I saw that the amount of compromised records in the TJX data breach had doubled.

Interestingly enough, the allegation that the amount of compromised records had risen from 45 to 90 million wasn't brought forward by the folks at TJX. This new revelation was reported by the banking industry. They also reported at least $151 million in fraud losses have been associated with the breach.

This isn't the first time in recent history that the estimate of losses has risen dramatically. The Certegy breach jumped from 2.3 to 8.5 million records compromised. The media caught on to this increase as the result of a SEC filing.

Since this was part of ongoing civil case against TJX, the people revealing it have a powerful motivation to prove their point. TJX is still claiming that most of the information stolen was masked (hidden by asterisks), or had expired.

The $151 million in fraud losses startled me slightly since I had only seen one story about the information actually being used reported in the press. I'm referring to 6 people arrested in Florida, who went on a million dollar shopping spree and were later caught.

After doing a Google News Search, I was able to find one more story about a Ukrainian indivdual, who was caught in Turkey trying to sell some of the data.

In the Boston Globe story I read about this, both the card issuers and TJX dodged Ross Kerber's attempts to quantify some of the more recent estimates of loss being made.

I wonder if in data breaches, anyone really knows, or all the parties involved put out whatever version of the facts that suits their own interest in the matter?

The fact that some of the people investigating the TJX debacle have now doubled their estimate of the amount of records compromised lends credence to this theory. Of course, that depends on which version of the story you want to take as gospel.

It's unlikely the hackers (who might know the most accurate figure) will ever admit to it, either. Doing so, would incriminate themselves, and besides that, it probably isn't good for the business they are in. When a data breach is discovered, the fact that they have stolen the information is made public and it is (from their standpoint) compromised.

In fact, from the criminal's perspective (my speculation), the most profitable information they have is data no one knows they've stolen yet. I'd be curious to discover exactly when all this fraud occurred. Did it occur after the breach was made public, or before it?

Perhaps that is why very little of the information from data breaches seems to be used? Quite simply, it probably has little value to the criminal element, once everyone knows it's been compromised.

If you were a identity thief would you want to buy any of the information from the TJX data breach? The bottom line is that it would probably be dangerous to use, and it likely wouldn't even pass muster in most of the payment card authorization systems.

After all -- knowingly using it, would probably make them a statistic -- or one of the less than one-percent of identity thieves that get caught.

There is no doubt that there is a lot of personal and financial information being made available to criminals. Routinely, we see stories where the information is sold (e-commerce style) over the Internet.

The amount of known sources, where data has been stolen has gotten out of hand, also. The Privacy Rights Clearinghouse, Attrition.org and PogoWasRight all are making a valiant attempt to keep records of the known data breaches -- but with the lack of transparency in most of these data breaches -- it's unlikely they are going to be able to document the full scope of the problem,

There are probably many more data breaches out there that go unreported, or the entities who were breached have no idea that they occurred.

Until we start going after the source of the problem (the criminals), the problem of data breaches and identity theft will continue to grow. As we continue to bury our heads in the sand and minimize the problem, the criminals doing this will likely be laughing all the way to the bank!

Boston Globe article about the new statistics in the TJX breach (well-written), here.

Saturday, October 20, 2007

Payment card fraud victims being denied compensation

Apparently, fraudsters are now able to clone some payment cards, assign a new PIN -- and it appears that the customer's old PIN was used when the bank reviews the transactions.

Card Guide (UK) is reporting:

The Chip and Pin technology that has been in use in the UK over recent years is supposed to be practically fraud proof, but this is not the case, as thieves can clone cards and put a new PIN number onto the card – this is known as a YES card.

However, it appears to the bank that the original card and PIN have been used, and therefore banks claim that either the customer carried out the transaction themselves or they gave their PIN number to someone or were careless with the security of their PIN.

Card Guide story, here.

There have been many instances, where payment card thieves were able to get card details, along with the PIN numbers. It can happen to just about anyone, even when they are being careful.

If you have had a fraud claim denied because the bank claims you were careless, you might want to read about instances (substantiated), where PIN details were stolen using pretty sophisticated methods, here.

Of course, there are and always have been people, who try to claim fraud for their own financial advantage. Because of this, it seems some innocent people are getting their claims denied (my opinion).

Figuring out, who is guilty of this is getting harder all the time.

My guess is that with all the fraud involving payment cards, it's no longer an expense the banks can continue to write-off as a cost of doing business.

Banks denying claims because they say a customer compromised their own information is nothing new.

One example of how this happens can be seen on BankofAmericaSucks.com, here.

I guess all the zero liability ads we see all the time aren't exactly one-hundred accurate?

If you have wrongfully had a claim denied, I've seen individuals made whole by escalating the matter with the financial institution. In some instances, using a consumer advocate was necessary.

On a final note, in most businesses, the cost of fraud is passed off to everyone, when we pay more for goods and services. The truth is we are all held liable for the cost of fraud!

Friday, October 05, 2007

Retailers call for a level playing field on data security

The data breach at TJX, which compromised approximately 45 million people has spawned a looming battle between retailers and the financial industry. At stake is who will bear the future costs of data breaches, which are becoming more expensive than ever before.

Thus far, we've seen legislation introduced to hold retailers responsible and calls for PCI data security standards. Legislation has been passed in Minnesota and is awaiting Governor Schwarzenegger's signature in California.

In any disagreement, there are two sides to a story -- and now the National Retail Federation (NRF) is bringing up what I consider is a valid point -- which is if they weren't required to store all this information, it would be harder to steal.

Under current rules, they are required to maintain too much information for 18 months, or face what are known as chargebacks.

Chargebacks are when a customer requests a refund from their card issuer, normally because of fraud. Please note that some dishonest customers claim fraud, when it never occurred. Additionally, the payment card industry sets the due diligence standards when accepting their cards and actively promotes their use.

The bottom line is -- merchants can accept payments, follow all the rules, and if they can't provide the required information -- they get charged for it, anyway.

With all the fraud that results from payment cards, this could get pretty expensive for a retailer, if they fail to control it.

Saying all this, we need to consider the bigger picture, which is the best way to protect data is to limit how many places it is being stored. This principle should be considered in a lot of other places besides retailers, also.

Mark Jewell of the AP is reporting:
The National Retail Federation on Thursday urged a card industry organization to stop requiring retailers to keep customers' card numbers for up to 18 months.

The stored data helps track product returns and disputed or suspicious transactions. But retailers say the data would be more secure if only credit card companies and banks that issue the cards stored it.

"It makes more sense for credit card companies to protect their data from thieves by keeping it in a relatively few secure locations than to expect millions of merchants scattered across the nation to lock up their data for them," David Hogan, the retail federation's chief information officer, said in a strongly worded letter.
In the article, Mr. Hogan brings up the very reason that retailers have been holding on to what some consider, too much information:

Hogan said in an interview that retailers routinely hold onto information because credit card companies ask them to produce data from transactions as old as 18 months to verify product returns and protect against fraud. If retailers can't produce data showing the product was legitimately purchased, they can end up reimbursing banks and card companies, Hogan said.
Only 44 percent of large retailers are now PCI compliant. This month, the larger retailer's banks will start facing fines for failing to become compliant. Banks that service medium size retailers will start facing fines in January.

This doesn't even take into account smaller merchants, who often are victimized the most by fraud, and chargebacks.

In case you don't understand how chargebacks can be a burden to a merchant, I've included a YouTube video at the bottom of this post, where a small merchant rants about chargebacks from PayPal.

The frustration expressed in this video is the same one felt by a lot of merchants (retailers).

The basic issue in all this is who will end up paying for it. Since no business remains solvent if they are losing money, the costs are going to end up being passed on to the consumer.

So far as the NRF's point, I think it is entirely valid. If retailers didn't have to store all this data, it would be one less place, where criminals could access it.

After all, while data breaches at retailers have gotten a lot of attention recently, they are not the only place they are occurring.

If you are interested in seeing what I mean by this the Privacy Rights Clearinghouse, PogoWasRight and Attrition.org all try to keep track of as many of them as they can.

All of them will tell you that their efforts only document the known breaches. There are probably many more that no one knows about -- and the last I heard -- the criminals behind them keep this a closely guarded secret.

After all, disclosure of a data breach impacts their bottom lines, also.

My personal solution is for everyone to get together and go after the real people behind this problem, or the criminals. Everyone would benefit from this!

My guess is they (the criminals) could care less, who ends up paying for all the damage they are causing.

AP story, here.

National Retail Federation (NRF) press release, here.

Here is the YouTube video (mentioned above), which reflects a small merchant's frustrations with the chargeback process. Please note that smaller merchants are bound to have a stake in what becomes of this controversy, also.

(YouTube video courtesy of Terry)

Wednesday, September 26, 2007

Did Vladuz hack eBay, or is stockpiled stolen information being used to make it look like he did?


(Picture courtesy of Yahoo Group, eBay_scamkillers)

There is a lot of speculation that eBay was hacked once again, and that Vladuz might be behind the latest episode.

Vladuz, who takes his name from a famous Romanian prince, Vlad Tepes, has plagued eBay with a string of hacking attacks in the past. Vlad Tepes was the inspiration for the novel, Dracula. In Internet folklore, Romanian scammers are often referred to as "Vlads."

Of course, eBay is denying that they were actually hacked. I'll let the reader form their own opinion.

Auction Bytes (Ina Steiner) is reporting:

eBay closed its Trust & Safety discussion board for hours on Tuesday after threads began appearing listing the names and addresses of eBay members. eBay spokesperson Nichola Sharpe said, "We think the fraudster obtained the eBay User names and IDs from previous account takeovers." The credit card information that was published alongside 1,200 names, User IDs and addresses were not associated with the financial information on file for those users at eBay or PayPal, Sharpe said.

Unfortunately, with the amount of account-takeovers caused by Phishing, eBay can suggest other ways the information might have been stolen. Phishing is where users are tricked into giving up their personal details, or downloading malware (crimeware), which steals it right off their hard drive.

I don't know which is worse, that they were hacked in this incident, or that all this information was compromised a long time ago? If it were compromised a long time ago, as eBay states, how much more compromised eBay information is out there?

The Cappnonymous Buds Blog has put together a pretty visual demonstration that makes a pretty good argument that eBay was hacked.

Account-takeovers enable criminals to scam others, using someone else's information. They can also be used to fence (sell) stolen merchandise with a high degree of anonymity.

It should also be noted that stolen payment(credit/debit) card details are often used to purchase the merchandise, which is then fenced.

To cover their tracks, the scammers often dupe people into laundering the proceeds of these sales in work-at-home (job) scams and wiring the money, normally across a border.

Whether Vladuz is behind this latest attack remains to be seen. But the fact remains, that there is a lot of fairly organized crime targeting eBay (my opinion) and other auction sites, on a daily basis.

Previous posts, I've written about eBay and auction fraud can be read, here.

In case anyone is interested in the graphic photo at the top, here is a post I did about a Yahoo Group that call themselves the eBay_scamkillers.

They are an all volunteer group, many of whom have impressive credentials, that are responsible for putting a lot of eBay scammers, where the sun don't shine (prison).

Sunday, September 23, 2007

TJX class action settlement only addresses about one percent of the total people compromised

Friday evening, MarketWatch announced that TJX -- who suffered a data breach compromising over 45 million of their customers --has agreed to settle the class action lawsuits that were filed against them after the data breach was disclosed.

The class action lawsuits referred to were filed in both the United States and Canada.

Since most of the financial losses have been incurred by financial institutions -- who had to reissue the compromised cards and settle the fraud claims -- this settlement appears to primarily address the customers compromised by the breach of TJX's refund database.

This would amount to about 455,000 people, or one percent of the total number of people compromised.

Another issue that is still pending is how information is stored, and who will be responsible for paying for the administrative costs arising from data breaches in the future. Consumers Union is pushing that one of these bills, already passed in California, be signed into law. Minnesota has already passed legislation that addresses this.

MarketWatch reports:
Under the settlement, which is subject to court approval, TJX will offer three years of credit monitoring and identity theft insurance to customers who returned merchandise without a receipt and to whom the company sent letters reporting that their driver's licenses or other identifying information may have been compromised.

TJX will also reimburse the customers for documented costs of certain license replacements and certain losses from identity theft if identification numbers compromised were the same as their Social Security numbers.

The company will hold a one-time three-day customer appreciation event, in 2008 or later, at which prices will be reduced by 15%.
One thing that concerns me is that the settlement offer states that one of the requirements to receive compensation will be that the identification number compromised has to match their Social Security number.

I guess that TJX and their affiliates don't want to address the rising phenomenon of synthetic identity theft? When synthetic identity theft is committed different parts of a persons identity are crafted to create a new one.

Stephen Coggeshell of ID Analytics was recently quoted as saying:
Five years ago, this crime was hardly seen. Eighty-five to 90 percent of identity fraud is really this synthetic ID fraud, as opposed to the true name identity theft.
Just because the identity and the Social Security number were not compromised together doesn't assure that that the person involved will not become a victim.

This led me to wonder how many Social Security numbers could have been compromised? The answer was right on a FAQ sheet on the TJX site:
We do not receive or store customer social security numbers per se. However, the drivers' license or military ID numbers customers provide us in unreceipted merchandise return transactions are, in some cases and in some states, the same numbers as their social security numbers. We are writing directly to customers we were able to specifically identify whose drivers' license, military or state ID numbers, together with their names and addresses, were found in the information believed compromised and identifying where we believe those numbers may be social security numbers.

Laws have been passed that prohibit the practice of placing Social Security numbers on identification documents.

In the identity theft world -- which is what the concern about this data breach is all about, when a SSN or SIN (in Canada) is compromised -- the criminal compromising the information has all the information necessary to complete a full identity assumption.

In the dark world of Internet forums that sell this information, a complete identity (SSN, or SIN included) is often referred to as a "full." The complete information on a person is simply worth a little more money to the criminals purchasing it.

Retail criminals, who causes billions in losses a year, often refund the merchandise to launder the proceeds of their efforts into cash. This was the very reason -- most retailers implemented databases to track the information of people, who show up at refund desks -- a little too frequently.

With the increasing availability of fake identification and bogus financial instruments -- already being used at retailers to steal merchandise, with a focus on high-value items that are locked up -- it's likely that a lot of the information in these databases isn't completely accurate.

I would guess that the same people, using the bogus financial instruments, purchase the merchandise with them and then head to the refund counter.

So far as the TJX offer to settle this portion of their liability, it still has to be accepted by the court. Of even greater importance is that retailers need to take a hard look at how these refund databases are protected -- and -- whether or not, they are as effective in stopping refund fraud as they used to be.

For more information on the issue of using Social Security numbers on identification documents, the Privacy Rights Clearinghouse has a document, here.

The University of California submitted an interesting document to the Federal Trade Commission on the subject of synthetic identity theft, which can be seen, here.

Last, but not least, Tom Fragala at Truston put together a pretty neat blog post with a lot of references about synthetic identity theft, here.

Saturday, September 08, 2007

SIRAS PI - tracking theft to the source


Graphic demonstration of anti-theft technology courtesy of SIRAS.com.

Criminals, who steal goods, whether with bogus financial instruments, or by more physical means might be in for a little surprise if the merchandise is protected by SIRAS PI.

Last week, SIRAS made this announcement in a press release:

SIRAS.com, the pioneer in Point-Of-Sale Electronic Product Registration used by leading manufacturers and retailers, has announced the nationwide launch of SIRAS P.I., a groundbreaking initiative to aid law enforcement officials in determining whether products they recover are, in fact, stolen, and if so, from where. Piloted by the Mesa, Arizona Police Department, SIRAS’s P.I. (Product Information) Database has already proven to be effective in helping law enforcement officials identify stolen items, report suspicious items, and apprehend and convict thieves. The database will be available, free of charge, to police and law enforcement agencies nationwide.

The way SIRAS works is simple, but effective. It tracks a product by recording the UPC (Universal Product Code) and the product serial number. SIRAS has the capability to determine where merchandise was stolen, whether from a merchant, manufacturer, or individual.

Earlier this year, SIRAS did some testing that revealed a substantial reduction in TV and MP3 player losses on products, where their technology was being used.

If deployed properly at the merchant level -- it could also determine how an item was purchased, and whether or not -- the method of payment used was legitimate. In theory, a merchant could also use the technology to impact credit card chargeback and fraud check losses.

I say "deployed properly" and "in theory" because the information to accomplish this (sales data) belongs to the company using SIRAS technology. Because of this, the capability to track sales information would have to be implemented inside the company. At most larger companies, this information is already tracked and analyzed to prevent and detect dishonest activity.

For years, most high-theft (shrink) merchandise has been secured so a thief can't merely pick it up from a shelf. When high-theft merchandise that was secured is stolen, it's normally because of one of two reasons. It was purchased with a bogus financial instrument, or an insider was involved in the theft.

Other reasons for secured merchandise being stolen might be a theft, directly from the manufacturer, or a theft during the shipping (transport) process. In these instances, if the merchandise was registered at the manufacturer, SIRAS can identify the point of compromise, also.

Technology has made it a lot easier for criminals to obtain and use fraudulent forms of payment. Information being compromised (data breaches) and anonymous places to communicate like Internet chat rooms, have given a lot of common criminals access to bogus financial instruments.

Along with the increased availability of fraudulent forms of payment, obtaining counterfeit identification documents has become fairly easy, and the identity used on them normally belongs to someone else. This has made it easy for a lot of retail criminals to operate as someone else.

Because of these new trends, current systems that record personal information to prevent fraud are becoming less effective than they use to be. I often wonder (no one probably really knows) how much of the information contained in them is incorrect.

In the recent data breach at TJX, one of the systems compromised was their refund database. Stories have circulated recently about the wrong people being pegged as frequent refunders, or bad check writers after their identities were stolen.

Neither one of these situations fosters good will, or trust with customers. Besides that, data breaches are becoming costly. The last I heard TJX has spent approximately $256 million dealing with the breach. With pending litigation, the cost is liable to keep going up.

With SIRAS, using personal information isn't necessary to determine, whether or not, a return is legitimate. SIRAS already has proven to be highly effective in reducing refund fraud without asking for one item of personal information.

An example of how some of the TJX data was used in a retail theft scenario can be seen, here.

Given that criminals that steal merchandise want to turn it into money, two methods are normally used. They either refund it somewhere, or fence it. Auction sites provide an easy and when combined with account-takeover activity (anonymous) venue for criminals to fence merchandise.

In the auction world, seller accounts are taken over all the time. This normally occurs when seller accounts are compromised by a phenomenon known as phishing. Phishing occurs when a person is tricked into giving up their access information after receiving a spam e-mail.

Compromised seller accounts are sold on the Internet the same way financial information is, and there is a trend in DIY (do-it-yourself) phishing kits being sold that enable non-technical criminals to get into the game.

eBay and PayPal are two of the most heavily phished brands. Once these accounts are compromised (taken over), they are used by criminals to fence merchandise and launder the monetary proceeds of their illicit sales.

Another growing trend related to phishing is when malware, also sometimes known as crimeware is used to steal information. The difference here is information is stolen from systems automatically (normally by keylogging software) and social engineering (trickery) is no longer necessary to get people to give up information.

Malware is often picked up by a computer system by clicking on a spam e-mail link, or by visiting a website designed to inject the software on a system. PC World recently did one of the many stories floating around about malware being sold on the Internet in the form of DIY kits.

In the story they wrote:

The global market for criminal malware now operates like a supermarket, complete with special offers and volume discounts, a security company has discovered.

Here again, this capability enables not very technically inclined criminals to get into the game. This has become a growing problem and I expect it to get worse before it gets better.

With the availability of all this personal and financial information, being sold on an economy of scale, current fraud protection systems are routinely being compromised by a lot of criminals.

There is an old saying in the investigations world, which is if you want to solve a crime, the easiest way is to follow the money.

SIRAS takes this one step further by tracking both the merchandise and can track the money ( if programmed to do so by the user). When you do this, the odds are far greater that the true culprit will be identified. They are normally associated with either the money, and or the merchandise.

Since the technology records both physical and UPC information, the database can determine exactly where the merchandise was compromised (stolen). Given that many merchants use digital video systems -- which are capable of storing video footage for a long time, it's also possible to obtain video evidence of the original transaction -- when sales information has been programmed to tie into the technology.

SIRAS has been used by select manufacturers and merchants for several years now -- however a new initiative, SIRAS PI, which was tested with Mesa PD -- makes the database available to law enforcement agencies free of charge.

Law enforcement can access the database either via the Internet, or by telephone. They can also add items to the database when they are reported stolen. If someone later tries to refund the merchandise at a participating retailer, the transaction can be automatically flagged.

Although a lot of fencing now occurs on the Internet, the technology is equally as effective in investigating more traditional property crimes, also. The bottom line is once merchandise is discovered, it can be tracked by SIRAS, if the item has been registered.

Recently, Chris Hansen (MSNBC), did a story about iPod theft. When Apple was approached about tracking the merchandise using Apple's registration database, they decided not to cooperate with MSNBC.

Undaunted by this, MSNBC purchased a bunch of iPods and engineered the registration disc to send them the information when the iPod was registered. They then left the iPods (new in the box) unattended, let them get stolen and tracked them to the crooks once the iPod was registered.

Chris Hansen made an excellent point on how databases can track stolen merchandise -- but in this instance, brand new iPods had to be left in public places to be stolen -- then registered to make the point.

If Apple used SIRAS technology to protect their merchandise -- it would have already been traceable, even if it was stolen from an individual -- who didn't provide the thief with the registration disc. It also would eliminate privacy concerns, which might be why Apple didn't want to cooperate with the MSNBC investigation?

When registering any product, a lot of personal information is normally asked for.

In any event, most criminals of the smarter variety aren't going to provide their personal information in the registration process. Most of them shy away from doing things, which might get them caught.

It would be interesting to have MSNBC, or another investigative news source do the same story with merchandise protected by SIRAS. The story might expose more than people, who stole because of an almost "too good to be true" opportunity was provided to them.

MSNBC iJacking story, here.

This brings up another potential benefit to this technology. Expensive portable electronics and other expensive toys like mountain bikes are stolen from the people who buy them (customers) all the time. Using SIRAS technology might even be a selling point that instills customer trust in the product they are purchasing.

This technology has prevention/investigation applications for corporations, law enforcement agencies and individuals, alike. It also doesn't require using people's personal information, which isn't as effective as it used to be, and is becoming more unpopular all the time.

In my opinion, this technology has the ability to make it a lot harder to get away with stealing merchandise and converting it into money.

Of course, the more it is used, the more effective it will become. Databases have a tendency to do this, or become more useful as they contain more information.

There are a lot of anti-theft/fraud technologies that claim to prevent theft/fraud. Very few of them also claim to be able to go after and hold the criminals committing the fraud/theft personally accountable.

The last I heard, most criminals still fear getting caught!

If you would like more information on the organized trade in counterfeit identification documents, the story of Suad Leija can be seen, here.

Suad's story has been covered extensively in the media, including by Lou Dobbs. Currently, she is writing a book and I keep in touch with her occasionally.

More information about bogus financial instruments can be seen, here and here.

A chronology of data breaches is compiled by the Privacy Rights Clearinghouse, here.

The best source on phishing is the Anti-Phishing Working Group and if you are interested in learning even more about phishing and want to see some totally fake banking sites, Artists Against 419 is another good place to visit.

Last, but not least, if you are interested in learning more about SIRAS PI, you can do so by visiting their site, here.

Saturday, July 21, 2007

Task Force puts child predator away for 10 years

There is nothing that disgusts me more than crimes against children, or crimes against the elderly. The anonymous nature of the Internet has made it easier for criminals to distribute child pornography, as well as, for child predators to have access to our young.

I happened to see a Department of Justice (DOJ) press release about one of these predators getting 10 years in prison for being involved in child pornograpy.

On Jan. 3, 2007, Thomas Lane pleaded guilty in U.S. District Court for the Southern District of Indiana in Indianapolis to one count of possession of child pornography. The government's evidence showed that the defendant possessed images and binders with photos of children engaged in sexually explicit conduct. The majority of the images, printed out and organized in the binders, also contained links to Internet Web site addresses. Lane had been previously convicted in 1998 for receipt of child pornography.


DOJ press release, here.

This was accomplished (investigated and prosecuted)by the Internet Crimes Against Children Task Force (ICAC).

Apparently, it was brought about as a result of Project Safe Childhood, which was put in place by Attorney General Alberto R. Gonzales in 2006.

Besides investigating this type of crime, they have a pretty good (my opinion) educational resource to educate all of us on this problem.

The DOJ website can be viewed, here.

Child pornography has been tied into organized crime, identity theft and payment card (credit/debit) card fraud. Here is a previous post, I did about how this occurs:

British citizens accused of child porn found to be fraud victims

In case you haven't seen it, the To Catch a Predator series (Dateline) made a lot of people aware of how serious a problem child predators are. Chris Hansen, who hosts the show, has a blog about the series, here.

If you suspect a crime against a child, it can be reported, here.

Wednesday, July 18, 2007

The battle over who is going to pay for data breaches heats up

The TJX data breach (45 million records and counting) is rapidly turning out to be the straw that broke the camel's back. Everyone seems to be worried about, who is going to bear the financial burden that data breaches are causing.

Cleve Doty at PrivacySpot.com writes:

Retailers will be forced to pay for data compromises when they violate industry standards of data protection under a new Minnesota law, detailed here. California and Texas are considering similar legislation, as noted here and here. The Minnesota law adopts Payment Card Industry Association (PCIA) data protection standards, which require that companies not retain data from a card, including security codes, PINs, and magnetic strip data, for more than 48 hours after a transaction is approved. If a data breach occurs and the retailer failed to comply with the card security protocol, then they will have to pay costs including: refunds for unauthorized purchases, reissuing cards, notifying cardholders, and closing and reopening accounts.
The article also stipulates that retailers could be charged for excessive fraud transactions that occur on their premises.

This interested me, especially given the recent criticism Target -- who has it's headquarters in Minnesota -- recently received for not verifying credit card transactions. Will this make them change their policy of ONLY relying on electronic data (magnetic stripe info) when accepting payment cards? Currently, they do not train their employees to check cards, or ask for identification.

The other strange thing at Target is that, although they've tightened up their return policy, they will gladly look up your payment card number (credit/debit) card to assist you in completing a refund. One of the basics of protecting a lot of this information is that it isn't stored for a long time?

One of the more common and most publicized losses by retailers are when thieves commit fraudulent refunds. I wonder how much merchandise is being stolen using fraudulent payment devices, then refunded?

Today, I'm picking on retailers, but the fact is that data breaches are occurring at a lot of places. For instance, institutions of higher learning, seem to be breached all the time. Furthermore, if you follow what tracking is available on data breaches (Privacy Rights Clearinghouse, Attrition.org, PogoWasRight), the financial services sector has had their share of breaches, also.

It amazes me that since the TJX breach, there has been a lot of focus on merchants. Sadly enough, this legislation will probably hurt smaller merchants more than it will larger ones.

Merchants feel strongly that the credit card companies have been unfairly charging them for a lot of things, including fraud. Recently, I did a post about a Merchant Bill of Rights, where merchants are banding together to fight for a better deal when dealing with the credit card industry.

Meanwhile, the deadline is looming for federal agencies to come up with a plan to address data breaches. Government agencies seem to be having their share of breaches, also.

We'll probably see a lot of infighting between all the different sectors being breached. Everyone seems to be worried about, who gets to pay for all of it, and how it might detract from all the money they've been making off people's personal information.

Maybe it would be better if everyone involved started working as a team and going after the real problem, which is that information is too easy to access and criminals are making too much money by stealing it.


Full story from PrivacySpot.com, here.

Tuesday, June 05, 2007

Merchants demand their rights from the payment (credit/debit) card industry!

Not very long ago, credit and debit (payment) card fraud was considered a cost of doing business. With carder forums and data breaches, the cost of payment card fraud has reached billions of dollars, and merchants, especially smaller ones, are being impacted in a negative manner.

There seems to be a looming battle on the horizon over, who is going to pay for all the fraud. Recently, in light of the TJX breach, legislation was introduced to charge more of the costs off to merchants.

Merchants have always been charged for a lot of fraud in the form of chargebacks. When I saw the proposed legislation, my first thought was how it would impact the smaller merchants, pretty harshly.

Additionally, merchants aren't only becoming more alarmed by fraud, but also by a perception that current fee structures are unfair, and deceptive. Interestingly enough, a lot of consumers feel the same way, also.


Today, I read an interesting press release about a movement to adopt a "Merchants Bill of Rights."


Recently, supporters of this bill did a survey of merchants, where they discovered:


  • Only 26 percent of participants believe they are being treated fairly by the debit/ credit/prepaid card processing industry.

  • Only 32 percent understand unfair card processing practices and how they impact their business.

  • Only 21 percent understand the rates, fees and surcharges they pay.

  • Only 15 percent believe they are charged the same as larger businesses.

The survey was sponsored by Heartland Payment Systems, who processes payment card transactions and payroll.


Heartland's CEO and Chairman, Bob Carr stated:

It’s clear that many owners of small and mid-sized businesses don’t understand the complexities of card acceptance. Yet, card acceptance is often one of the three largest expenses they incur. Business owners need to educate themselves so they can manage these costs. What they don’t know may be hurting their bottom line.


According to the press release, the bill of rights promotes fairness and transparency in card processing by identifying 10 fundamental rights:


The right to know the fee for every card transaction – and who’s charging it.



The right to know the markup of Visa and MasterCard fee increases.



The right to know all Visa and MasterCard fee reductions.



The right to know all transaction middlemen.



The right to know all surcharges and bill-backs.



The right to a dedicated local service representative.



The right to encrypted card numbers and secure transactions.



The right to real-time fraud and transaction monitoring.



The right to reasonable equipment costs.



The right to live customer support 24/7/365.



The effort has a home page, which can be viewed, here.


The page has a video for merchants to see if their rights are being violated, here.


The Association of Certified Fraud Examiners recognizes that small businesses suffer greater losses than larger ones do. I did a post on this subject, with the some tips on how to avoid becoming a victim, here.


In January, I did a post about how both consumers and merchants are calling for some reforms:


Congress needs to take a hard look at credit practices


In this post, I mentioned the Merchant's Payment Coalition, which is calling for greater oversight on some of this. Their page on unfair credit card fees can be viewed, here.


Even if you aren't a merchant, the truth is that these costs have to be passed off somewhere; otherwise merchants would go out of business. Who do you think ultimately pays for all this?

Wednesday, April 25, 2007

President's Identity Theft Task Force issues recommendations


The Identity Theft Task Force has issued the formal recommendations they've been putting together since May, 2006. The recommendations include feedback solicited from the general public.

The final report is comprehensive -- identifying all the issues that have made identity theft and the financial crimes that result from it -- a major concern in the public eye.

The report does (slightly) downplay the problem of data-breaches, noting no significant increase in financial crimes and identity theft from them. I'm not sure, I completely agree with this, but other's could probably argue this point with me. Despite this, it does make a lot of great recommendations on how to limit our exposure to the problem.

In all fairness, it's very difficult, if not impossible, to identify the original point of compromise in an identity theft case. In most cases, the best guess rule applies. With information being sold over the Internet, the criminal using the information probably isn't sure where it came from originally, either. And even if they were to tell us, most of them can't be considered 100 percent credible.

Underground carder forums seem to be selling personal and financial information, too inexpensively. This phenomenon ties the less sophisticated identity thieves with those of a more sophisticated (organized) nature. Given this, the problem has the ability to expand, rapidly.

As there is more demand, we might see more information being used in all sorts of crimes and Internet access is growing, rapidly.

Congress considered several bills on data breaches in their last session, but failed to pass any of them. Protecting against data breaches is going to be an expensive proposition and my guess is that there is a lot of lobbying going on by the organizations that will ultimately pay for protecting the information better.

The report calls for stricter laws and more aggressive enforcement, which is something that should be taken seriously. In my opinion, a large part of the problem is that identity theft is too easy to commit, extremely profitable, and consequences are minimal, if caught.

Also called for is more cooperation of an International nature, which is going to be a key part of any resolution to what is rapidly becoming a global problem.

The full report can be seen, here.

The Task Force's homepage, which has more good information, can be seen, here.

Friday, April 06, 2007

Retailers and the FBI band together to fight organized crime

Communication is probably the most effective tool in fighting financial crimes, especially those of the organized sort. Financial crooks (scam artists) thrive on a lack of communication and knowledge.

The retail industry realizes this and in partnership with the FBI is launching a secure tool that businesses and law enforcement can use to communicate criminal activity with each other. A simple, but powerful principle.

Here is the information on this new tool from the NRF site:
In response to an alarming rise in organized retail crime, the National Retail Federation and the Retail Industry Leaders Association, in collaboration with the Federal Bureau of Investigation, have teamed up to launch the Law Enforcement Retail Partnership Network (LERPnet), a secure national database that will allow retailers to share information through its unique web-based design. With LERPnet, retailers and law enforcement will be able to fight back against illegal activity including organized retail crime, burglaries, robberies, counterfeiting, and online auction fraud. The database will launch on April 9, 2007.

Full NRF press release, here.

More information on this tool can be seen by linking, here.

The Washington Post also did a good story covering this.

A lot of other industries and law enforcement agencies should follow this example. Developing better tools to communicate could help resolve the current epidemic, currently being seen in all types of financial crimes.

There is some evidence that the bad guys communicate with each other, regularly (carder forums). The good guys should do no less!

To close, Joe LaRocca, NRF vice president of loss prevention is saying:

“With this system, retailers are banding together with law enforcement to send a clear message to criminals: We will not tolerate your behavior and we will stop you.”