Showing posts with label pci data protection standards. Show all posts
Showing posts with label pci data protection standards. Show all posts

Wednesday, January 21, 2009

Will Heartland Become the Largest Data Breach in History?

According to a press release from Heartland Systems, a payment card processor, their data has been being compromised since sometime last year. On the site, Heartland set up to cover the incident, it says they promptly notified the Secret Service and hired two teams of forensic computer investigators to look into the case after they discovered their systems had been compromised.

Heartland was initially notified by Visa/Mastercard of suspicious activity, which led to malicious software being discovered in their system. The malware in question was harvesting and (obviously) transmitting data. In the press release, they state they believe the breach has been contained. Heartland claims no merchant data, social security numbers or unencrypted PINs were compromised. They were also quick to add that their check management systems, Canadian payroll, campus solutions, micropayments operations and recently acquired Network Services and Chockstone processing platforms had not been compromised, either.

It should be noted that in previous breaches, additional items were later discovered to have been compromised as the investigation progressed.

Brian Krebs at the Washington Post interviewed Robert Baldwin, Heartland's president and chief financial officer, who stated they don't know how many transactions were compromised. In the interview, Baldwin pointed out that since the card numbers compromised didn't have address information; it would be hard for fraudsters to use them in card-not-present (e-commmerce) transactions. Most e-commerce platforms validate the address tied to the card as a security measure. I thought about this for a second and remembered that Visa/Mastercard had warned Heartland about suspicious transactions. If there were suspicious transactions, I would deduct someone is using this data to commit fraud. Besides that, I doubt anyone sophisticated enough to pull this off would go to all this trouble (and potential legal exposure) if they couldn't use the information to make money. This is another thing that might suggest additional information will be discovered as the investigation progresses.

In the interview, Baldwin declined to name any of their customers, who were compromised. Heartland processes payments for about 250,000 customers and processes about 100 million transactions per month. He also said they will not be offering identity theft protection since not enough information was stolen to commit identity theft.

On the Truston blog, Tom Fragala, aptly pointed out that this equates to four billion transactions a year. Many are speculating that this will turn out to be the largest known data breach in history. Tom's company, which offers a privacy-friendly identity theft prevention and recovery service, offers a 45 day free-trial of their services. Even after the 45 days, the prevention part of the service is free.

Tom blogs on matters like this and wrote an interesting article pointing out the consumer protection features of debit and credit cards. Please note, debit cards offer less protection. The point is that if a card owner doesn't discover the fraud in a specified time period, they can be held liable for the financial loss. It's probably a good time for everyone to pay attention to their statements, carefully.

Given the mandatory notification laws, which have been passed in almost all 50 states, this is going to equate a lot of people that have to be notified. Simply stated, it's going to be a "notification nightmare." It should be noted that shutting down all the compromised cards and notifying victims is a substantial cost in any data breach.

SC Magazine also covered the story and got a quote from Rich Mogull, founder of IT security consultancy Securosis, who pointed out there is a trend of malicious software being planted somewhere in the processing system in all the high-profile data breaches seen in recent history. TJX (94 million cards compromised), Hannaford and CardSystems (40 million cards compromised) are all being cited as examples.

According to Visa, Heartland was validated as Payment Card Industry Data Security Standard (PCI DSS) compliant on April 30, 2008. They then stated this status was being reviewed. Trustwave is Heartland's PCI assessor. Hannaford was PCI compliant at the time they were compromised, also. According to the article in SC magazine, TrustWave wouldn't return calls to comment on this.

On the Heartland site, it mentions they are a founding supporter of the Merchant Bill of Rights, which advocates for and educates merchants on fair practices when they accept payment cards. Two of the biggest heartaches for merchants accepting payment cards are the interchange fees and becoming PCI compliant, which is considered an expensive process. Interchange fees are a tariff charged by the credit card companies on every transaction and according to the critics are not very equitable. Estimates have been made in the past that they equate to $30 billion in extra fees added to the cost-of-goods sold with payment cards, yearly. Ultimately, these are costs are often passed on to the consumer.

So far as PCI compliance — which now seems to have been proven ineffective in at least two instances — the National Retail Federation has responded by going on record to challenge the card issuers on their requirements to store data. Because of the cost, a lot of merchants have been slow to adopt PCI data-security standards and the merchants who are not in compliance face fines by the payment card industry.

Storing this data is required to prevent the third headache merchants face when accepting payment cards, or what is known as chargebacks. Chargebacks are when transactions are charged back to a merchant account because of alleged fraud. The NRF contends that being forced to maintain the data to protect themselves makes it easier to compromise.

Heartland is being challenged for releasing this information during the inauguration, when it was less likely to be a hot story. Although this seems to be the case, we need to realize the stakes in data-breaches are high. In the last breach involving a card processor (CardSystems), the card-issuers stopped doing business with the company and the end-result was the company is no longer in existence. Also, it should be pointed out that Heartland wouldn't be the only company that seemed to be very cautious when disclosing the fact that their data was compromised. Once disclosed, there is little doubt that the company in question faces some extremely unfavorable public exposure.

On a closing note, data breaches continue to occur at alarming rates. All sides of the equation need to come together and figure out solutions that work. One of them might be to upgrade the plastic to chip and PIN technology, which has become the standard in other countries. Nigeria was the most recent country to mandate this technology. While this might not directly stop data breaches, it would make it a lot harder to counterfeit the plastic, which is what the criminals use to cash-out the proceeds of data breaches with.

The other problem is that credit card fraud has been made too easy to commit. Card data and the tools to produce counterfeit cards are easy to obtain and even sold in chat rooms. A lot of this technology can also be bought on (what I consider) questionable sites, including eBay. Very few of these fraudsters get caught and because of this; it appears that the activity is getting more and more organized. Historically, the cost of all this seems to have been written off as a cost of doing business. In reality, a lot of these "costs" are passed on to the consumer in the form of higher interest rates and fees.

My prediction is that with the state credit is currently in with the sour economy, coupled with the increase in criminal activity, we are getting to the point where it is going to be hard to simply write-off all the financial costs. Until we start punishing the criminals effectively for this type of activity, it is going to continue to grow and probably prosper.

Update 2/13/09: It appears that the first arrests in the Heartland Data Breach have been made in Leon County, Florida. Three men (Tony Acreus, Jeremy Frazier and Timothy Johns) were encoding numbers stolen in the breach on gift cards and using them at Walmart.

The official press release from the authorities credits Walmart for supporting the investigation.

While it's great a few people got caught -- this probably only accounts for a small amount of the stolen data. My guess is that our three fraudsters bought the numbers via anonymous sources (probably on the Internet).

Wednesday, May 07, 2008

Stolen information from 40 financial and medical institutions discovered on rogue server

Once in awhile, I speculate that stolen information is a lot more valuable to the criminal element before it becomes apparent that it's been stolen. I've also speculated aloud that there is probably a lot more stolen information out there than we are aware of. The good folks at Finjan are well on their way to substantiating this speculation.

Yesterday, they announced the following on their malicious page of the month:

While we were examining malicious code, we came across a domain which was being used as a command and control for the Crimeware that was executed on attacked machines. The domain was also used as the “drop site” for private information being harvested by that Crimeware.

When we further examined this server, we found the stolen data left unprotected and available for anyone on the web (i.e. no access restrictions, no encryption whatsoever).

The server that we analyzed contained more than 1.4Gb of data (both business and personal related) collected from infected PCs, which consisted of 5,388 unique log files, that were traced back to 5,878 distinct IP addresses. Both email communications and web related data were found.
The information discovered was from 40 unnamed financial and medical institutions from several different continents. The server used to store this information was being moved frequently, but if found, anyone could access it.

They made the observation that last year, according to what statistics are available, 8.5 million records were compromised. One of these statistics, obtained from IC3 states that 20 percent of the 206,884 cases (roughly 40,000) were due to computer hacking. Finjan points out that on this one server, they discovered approximately 5,000 records.

I’ll let the reader do their own math, but if this is true there is probably a lot of unknown hacking activity happening in the wild.

Please note that all the kind people compiling statistics only know what is reported to them, and some of them have been very vocal in pointing this out. My personal guess is that there is so much stolen information out there that when any individual case is investigated, it’s almost impossible to do more than speculate, exactly where the point of compromise occurred.

Besides that, hackers are unlikely to want to reveal where they are stealing all their information from. Once revealed, it’s harder to use and not worth as much money.

The information on the server included compromised medical information, online banking information (including passwords) and complete logs of payment card (debit/credit) card transactions, including CVV2 information and the miscellaneous “extras.” This all occurred on “supposedly” secure sites.

I found this interesting because the merchants have been under fire for becoming compliant with PCI data security standards in light of a few highly publicized data breaches. Of course in the recent Hannaford case, they were compromised and had been certified as being PCI compliant. PCI data security procedures are the payment card industries own standards for protecting information.


Based on these findings, hackers don’t have to compromise a merchant to steal everything they need to commit financial crimes and it’s pretty obvious that financial institutions are being compromised, also.

Also found on the server was a lot of business proprietary information harvested from a lot of internal e-mail accounts. In the past year or so there seems to have been a lot of campaigns to obtain other than financial information from businesses. The clear intent in this activity is corporate espionage (my speculation).

Finjan reports that this particular theft campaign was made possible with a do-it-yourself (DIY) crimeware kit called the AdPack Toolkit. They also reported that this kit gives the user command and control functions, enabling them to execute admin functions with the illicit software.

Finjan is not revealing (they never do) exactly which institutions were compromised. Even though they are not revealing names, they did report the activity to law enforcement and the institutions involved.

Saturday, March 29, 2008

How did hackers plant malware at Hannaford Bros. and steal 4.2 million payment card numbers?

Hannford Brothers, the latest retailer to be compromised in a large scale data breach is reporting that hackers using malware breached their systems.

The next million dollar question (literally) is how was the malware (sometimes referred to as crimeware) dropped on their system? A lot of people are looking at this carefully because the company had been certified as meeting PCI (Payment Card Industry) data protection standards.

Ross Kerber at the Boston Globe, who gets the hat tip for breaking this latest development in the story wrote:

Data security specialists say the new details show how hackers have grown more adept at penetrating weak links in the systems that connect merchants and banks. In previous breaches, such as the record-setting intrusion at TJX Cos. of Framingham, where as many as 100 million card numbers were compromised, hackers took advantage of merchants who stored customer names and card data - sometimes in violation of payment industry standards - at central locations in their computer networks.

In contrast, Hannaford says it did not store customer information. The hackers who struck Hannaford mined a stream of data that the merchant and banks were not responsible for protecting under industry rules, industry specialists said.
Because hackers, criminals and misfits rarely give up their latest hacks, we'll have to be content with speculation from the experts.

Jaikumar Vijayan at ComputerWorld was able to get some expert speculation from "Mike Paquette, chief strategy officer at Top Layer Networks, a vendor of intrusion-prevention systems in Westboro, Mass." Bill Brenner at SearchSecurity.com wrote about increasing speculation that a dishonest insider planted the malware on Hannaford's network.

The insider theory intrigues me because it seems that most security breaches can be traced to a social cause. A dishonest human --who has been given access to a system -- can defeat a lot (most) computer security.

Going further into all the speculation has come about from the Hannaford announcement, I decided to see what the blogosphere had to say.

Securosis.com gives a lot of interesting perspective in their post, Picking Apart The Hannaford Breach- What Might Have Happened .

The post points out some interesting thoughts, such as that credit card numbers are useless without names (Hannaford claims no names, or social security numbers were stolen) and that the breach was most likely discovered at financial instiutions when customers complained about fraudulent transactions on their cards.

rmogull summed up his "admitted" speculation with:
In conclusion, it looks like some sort of a network breach (which could be anything from phishing/malware to compromise from a retail location to a full network hack). A sniffer was possibly installed, since it seems they don’t keep credit card information (again, assuming statements are true). The fraud was detected by the banks or credit card companies, then it took a little under two weeks to contain. Not great, and indicative of either a little sophistication on the attacker’s part, or a lack of sophistication on Hannaford’s part.
There are also some interesting comments with more speculation at the bottom of the post. From what I can gather a lot IT types read this blog.

In the end, as long as there is lack of transparency in data breaches, the best anyone can do is speculate. The reasons for a lack of transparency in data breaches are a mile long, encompassing everything from protecting ongoing investigative efforts to avoiding the financial pitfalls of all the litigation that arises after a data breach.

Of course, in more simple terms, it might also mean that no one is really sure?

Given that, I wonder if anyone can be really sure that their personal information is safe? Your guess is probably as good as mine!

Previous posts on this blog about the Hannaford Data Breach:

Security vendor removes Hannaford as a client on their site after data breach is revealed!

Hannaford Brothers data breach might reveal current security standards are outdated

Tuesday, March 18, 2008

Hannaford Brothers data breach might reveal current security standards are outdated

Hannaford Bros. Co., a grocery retailer based in the Eastern United States is the latest corporation to be victimized by a substantial data breach. Saying that, customers of Hannaford Bros. are going to be victimized, also. So will a lot of financial institutions, who have to deal with the fraud claims and trying to prevent the information from being used.

Whenever a data breach of this magnitude occurs, there are a lot of victims.

This breach occurred despite that fact Hannaford Bros. had met the payment card industry (PCI) standards for data protection and were not using wireless technology to transmit unencrypted data. Both of these factors were said to have caused the now infamous TJX breach, where approximately 98 million records were compromised.

This time only a reported 4.2 million records have been stolen, but it's still early in the game and historically these estimates tend to blossom with time.

A press release from Hannaford revealed that no personal information was stolen in this occurrence and that only payment card (credit/debit) card numbers are at risk.

Additionally, there have been 1800 reported cases of fraud tied into this data breach thus far.

Today, the AP was able to get a comment from their corporate headquarters:

It was during the card approval process that more than 4 million customer accounts at grocery stores in the Northeast and Florida were exposed to fraud, even though the company meets the latest standards for data security, a spokeswoman said Tuesday.

Hannaford Bros. Co. doesn't yet know how the breach — which began Dec. 7 and ended March 10 — occurred, said Carol Eleazer, vice president of marketing for Hannaford, based in Scarborough.

About 4.2 million credit and debit card numbers were exposed and at least 1,800 stolen during the seconds it takes for that information to travel to credit card companies for approval after customers swiped their cards in checkout-line machines, Eleazer said.

Brian Krebs of the Washington Post, who does the Security Fix blog quoted an industry expert, Bryan Sartin at Cybertrust as stating:

"I would say a trend we're seeing hitting a lot of retailers right now is that these organizations can be [compliant with the credit card industry security standards] and still have customer data stolen," Sartin said. "The data in transit is allowed to traverse private links and internal infrastructure without being encrypted, and the attackers are taking advantage of that."

Once these systems have been compromised, Sartin said, the attackers typically eavesdrop on the network using "sniffer" programs that can extract credit and debit card data as it moves across the wire, before it even leaves the store's network.
If the theory in Security Fix is pans out (probably will), some precedents might exist for the basic method the hackers used. The incidents, I will reference don't sound as sophisticated as what Mr. Sartin is describing, but they happened about a year ago and hacking methods tend to mature with age.

Stop and Shop was the subject of a data breach a little over a year ago. In this case, PIN pads were being replaced with "look-alike" devices that captured all the payment card details. This hardware was later removed to download all the information that had been captured when unsuspecting customers swiped their cards.

Shortly thereafter, another compromise of this type was reported in Edmonton, Canada. In this case, a blue tooth device was used to transmit the information to a waiting car in the parking lot.

The trend with PIN pad replacement continued with a smaller breach at a grocer in the San Francisco Bay area, Albertsons in April of 2007. At the time, I had the pleasure of speaking with Blanca Torres, who was doing an article on the story.

Interestingly enough, up North in Canada, where payment card skimming has increased six-fold in recent years, an announcement was made that they plan to introduce a smart card. This technology, which is known as "chip and PIN" is already in use in Great Britain and France.

The AHN story about this by Vittorio Hernandez included (what I consider) a sage comment:

But Peter Woolford of the Retail Council of Canada is wary that although the smart cards appear to be effective in reducing incidents of fraud, sinister minds may one day find a way to hack the smart chips. "Anything the human brain puts together, another human brain can take apart," Woolford pointed out.
Sadly, once this all pans out, it will likely reveal that PCI data protection standards can and will be compromised in the future. The reason, I say sad is because a lot of retailers have spent a lot of money becoming compliant.

Throw in all the finger pointing and litigation between the different parties in all these breaches and I fear we're going to be fighting a very costly battle over what is becoming a too common item in the news.

I'll sum this post up with a rant, I wrote when the TJX breach was attracting a lot of attention:

While everyone sues TJX, the criminals are laughing all the way to the bank

Press release from Hannaford about the breach, here. They list a telephone number on it, where more information can be obtained if you think you've become a statistic.

Saturday, November 10, 2007

Visa's big break to TJX on security standards during their data breach!

The TJX data breach -- which in case you haven't heard just doubled it's estimate of records compromised from 45 to 90 million -- has caused a lot of finger pointing between the financial and retail sectors.

Of course, this was revealed in court filings (like the revelation below) and I'll be surprised if anyone is willing to answer any questions about it.

The latest is that Visa knew that TJX had "extensive security problems," but chose to let them off the hook to become PCI compliant until 2009.

Evan Schuman of EWeek reports:

Credit card company Visa knew in late 2005 of the extensive security problems at TJX, but decided to give the retailer permission to remain non-compliant through Dec. 31, 2008, according to documents filed in federal court on Nov. 8.

The Dec. 29, 2005, letter from Joseph Majka, a fraud control vice president for Visa, was written months after cyber-thieves had already secretly infiltrated TJX's systems, starting the work that would ultimately become the worst data breach in credit card history.

Ironically -- while hackers were happily stealing a lot of PEOPLE's personal and financial information -- Visa wrote TJX telling them they would be holding off from fining them as long as they were diligent in fixing the problem.

In 2007, Visa fined one of TJX's banks before the deadline had expired.

PCI compliance standards are enforced by the payment card industry themselves. All that seems to be coming out of the largest data breach in history is a lot of finger pointing and litigation, which like fines, are driven by a financial incentive.

I hate to say it, but neither side of the fence wants to stop using plastic. They both are making billions of dollars in the process.

Perhaps -- if an entity with no financial stake in all this dictated the standards --the people having their information stolen by criminals would be a LOT better off.

The question is when are people (customers) going to come first?

eWeek story, here.

Friday, October 05, 2007

Retailers call for a level playing field on data security

The data breach at TJX, which compromised approximately 45 million people has spawned a looming battle between retailers and the financial industry. At stake is who will bear the future costs of data breaches, which are becoming more expensive than ever before.

Thus far, we've seen legislation introduced to hold retailers responsible and calls for PCI data security standards. Legislation has been passed in Minnesota and is awaiting Governor Schwarzenegger's signature in California.

In any disagreement, there are two sides to a story -- and now the National Retail Federation (NRF) is bringing up what I consider is a valid point -- which is if they weren't required to store all this information, it would be harder to steal.

Under current rules, they are required to maintain too much information for 18 months, or face what are known as chargebacks.

Chargebacks are when a customer requests a refund from their card issuer, normally because of fraud. Please note that some dishonest customers claim fraud, when it never occurred. Additionally, the payment card industry sets the due diligence standards when accepting their cards and actively promotes their use.

The bottom line is -- merchants can accept payments, follow all the rules, and if they can't provide the required information -- they get charged for it, anyway.

With all the fraud that results from payment cards, this could get pretty expensive for a retailer, if they fail to control it.

Saying all this, we need to consider the bigger picture, which is the best way to protect data is to limit how many places it is being stored. This principle should be considered in a lot of other places besides retailers, also.

Mark Jewell of the AP is reporting:
The National Retail Federation on Thursday urged a card industry organization to stop requiring retailers to keep customers' card numbers for up to 18 months.

The stored data helps track product returns and disputed or suspicious transactions. But retailers say the data would be more secure if only credit card companies and banks that issue the cards stored it.

"It makes more sense for credit card companies to protect their data from thieves by keeping it in a relatively few secure locations than to expect millions of merchants scattered across the nation to lock up their data for them," David Hogan, the retail federation's chief information officer, said in a strongly worded letter.
In the article, Mr. Hogan brings up the very reason that retailers have been holding on to what some consider, too much information:

Hogan said in an interview that retailers routinely hold onto information because credit card companies ask them to produce data from transactions as old as 18 months to verify product returns and protect against fraud. If retailers can't produce data showing the product was legitimately purchased, they can end up reimbursing banks and card companies, Hogan said.
Only 44 percent of large retailers are now PCI compliant. This month, the larger retailer's banks will start facing fines for failing to become compliant. Banks that service medium size retailers will start facing fines in January.

This doesn't even take into account smaller merchants, who often are victimized the most by fraud, and chargebacks.

In case you don't understand how chargebacks can be a burden to a merchant, I've included a YouTube video at the bottom of this post, where a small merchant rants about chargebacks from PayPal.

The frustration expressed in this video is the same one felt by a lot of merchants (retailers).

The basic issue in all this is who will end up paying for it. Since no business remains solvent if they are losing money, the costs are going to end up being passed on to the consumer.

So far as the NRF's point, I think it is entirely valid. If retailers didn't have to store all this data, it would be one less place, where criminals could access it.

After all, while data breaches at retailers have gotten a lot of attention recently, they are not the only place they are occurring.

If you are interested in seeing what I mean by this the Privacy Rights Clearinghouse, PogoWasRight and Attrition.org all try to keep track of as many of them as they can.

All of them will tell you that their efforts only document the known breaches. There are probably many more that no one knows about -- and the last I heard -- the criminals behind them keep this a closely guarded secret.

After all, disclosure of a data breach impacts their bottom lines, also.

My personal solution is for everyone to get together and go after the real people behind this problem, or the criminals. Everyone would benefit from this!

My guess is they (the criminals) could care less, who ends up paying for all the damage they are causing.

AP story, here.

National Retail Federation (NRF) press release, here.

Here is the YouTube video (mentioned above), which reflects a small merchant's frustrations with the chargeback process. Please note that smaller merchants are bound to have a stake in what becomes of this controversy, also.

(YouTube video courtesy of Terry)

Wednesday, July 18, 2007

The battle over who is going to pay for data breaches heats up

The TJX data breach (45 million records and counting) is rapidly turning out to be the straw that broke the camel's back. Everyone seems to be worried about, who is going to bear the financial burden that data breaches are causing.

Cleve Doty at PrivacySpot.com writes:

Retailers will be forced to pay for data compromises when they violate industry standards of data protection under a new Minnesota law, detailed here. California and Texas are considering similar legislation, as noted here and here. The Minnesota law adopts Payment Card Industry Association (PCIA) data protection standards, which require that companies not retain data from a card, including security codes, PINs, and magnetic strip data, for more than 48 hours after a transaction is approved. If a data breach occurs and the retailer failed to comply with the card security protocol, then they will have to pay costs including: refunds for unauthorized purchases, reissuing cards, notifying cardholders, and closing and reopening accounts.
The article also stipulates that retailers could be charged for excessive fraud transactions that occur on their premises.

This interested me, especially given the recent criticism Target -- who has it's headquarters in Minnesota -- recently received for not verifying credit card transactions. Will this make them change their policy of ONLY relying on electronic data (magnetic stripe info) when accepting payment cards? Currently, they do not train their employees to check cards, or ask for identification.

The other strange thing at Target is that, although they've tightened up their return policy, they will gladly look up your payment card number (credit/debit) card to assist you in completing a refund. One of the basics of protecting a lot of this information is that it isn't stored for a long time?

One of the more common and most publicized losses by retailers are when thieves commit fraudulent refunds. I wonder how much merchandise is being stolen using fraudulent payment devices, then refunded?

Today, I'm picking on retailers, but the fact is that data breaches are occurring at a lot of places. For instance, institutions of higher learning, seem to be breached all the time. Furthermore, if you follow what tracking is available on data breaches (Privacy Rights Clearinghouse, Attrition.org, PogoWasRight), the financial services sector has had their share of breaches, also.

It amazes me that since the TJX breach, there has been a lot of focus on merchants. Sadly enough, this legislation will probably hurt smaller merchants more than it will larger ones.

Merchants feel strongly that the credit card companies have been unfairly charging them for a lot of things, including fraud. Recently, I did a post about a Merchant Bill of Rights, where merchants are banding together to fight for a better deal when dealing with the credit card industry.

Meanwhile, the deadline is looming for federal agencies to come up with a plan to address data breaches. Government agencies seem to be having their share of breaches, also.

We'll probably see a lot of infighting between all the different sectors being breached. Everyone seems to be worried about, who gets to pay for all of it, and how it might detract from all the money they've been making off people's personal information.

Maybe it would be better if everyone involved started working as a team and going after the real problem, which is that information is too easy to access and criminals are making too much money by stealing it.


Full story from PrivacySpot.com, here.

Saturday, June 02, 2007

It is no wonder why skimming (credit/debit card fraud) is becoming a nasty problem!


Skimming credit and debit cards has become too easy with the irresponsible sale of technology. All the necessary techie devices to commit what many consider a "high tech crime" are being sold on the Internet - even on auction sites - such as eBay.

Yesterday, I read about an arrest of one of the Internet vendors by the Calgary Police, after they were tipped off by the United States Secret Service (USSS).

Here is what the press release from the Calgary Police Department said:
In January 2006, investigators with the U.S. Secret Service specializing in payment card fraud and Internet crime, identified a person using the Internet name of “Dron,” who was advertising skimming equipment for sale over the Internet.

A possible Calgary connection was identified and investigators assigned to the Calgary Police Service Commercial Crime Unit were involved in the investigation.

A joint, cross-border investigation was initiated. A Calgary resident was identified as the alleged manufacturer and exporter of devices which could be used for skimming data from debit and credit cards. With the assistance of other CPS units, the Calgary case has been successfully concluded.

There isn't a lot of information on how Dron was advertising his wares on the Internet, but the sad truth is he probably isn't the only vendor selling these devices.

I checked eBay (this morning) and devices that could be used to skim payment card details are being hawked (as usual) on the auction site.

In March, I wrote about a new variation (mutation) of skimming, where PIN pads were replaced at a Edmonton Wendys. The fake PIN pads are capable of transmitting card data and PIN numbers(using wireless technology) to fraudsters, who are probably sitting in a car in a parking lot.

I suspect the current fake PIN pads are being used to defeat PCI (payment card industry) data protection standards. The information is sent to the fraudster before it goes through the merchant's point of sale system.

PCI data protection standards have become a major concern lately, but it appears the criminals are already working on countermeasures that will get past them. Besides PIN pads, portable devices, used by dishonest insiders are a big problem right now, also.

Interestingly enough, even with all the media attention about PCI compliance, a large number of merchants have failed to implement them. A case to point at would be the recent TJX data breach, where at least 45 million records were compromised over a several year period.

In the Wendy's post, I identified a website called hackershomepage.com, which sells a lot of devices that can be used to commit financial crimes, including skimming. I just checked (and sadly) they are still up and open-for-business.

Of course, they publish a disclaimer on their page:
We WILL NOT answer emails from anyone asking about illegal activities, or how to use our products for illegal activities...they will automatically be deleted. All products are designed for testing and exploring the vulnerabilities of CUSTOMER-OWNED equipment, and no illegal use is encouraged or implied. We WILL NOT knowingly sell to anyone with the intent of using our products for illegal activities or uses. It is your responsibility to check the applicable laws in your city, state, and country.
This obviously is enough to keep them in business.
The PIN pad skimming variation has now been identified in both the Eastern and Western United States, as well as Canada.

Maybe if there were stricter controls on the sale of the devices that enable skimming, the problem wouldn't be so bad?

Meanwhile, expensive security technology (compliance) is being made mandatory. If history repeats itself, any technology designed (which is expensive in itself), will have a limited life span. I'm all for technological solutions, but if we don't back them up with consequences, they tend to have a limited effectiveness.

There needs to be more social solutions (laws) to bolster some of this expensive anti-fraud technology.

With millions of victims and billions of dollars being lost, I wonder why we allow this activity to be marketed over the Internet?

We are making hard working people, like USSS Agents and the Calgary Police, work pretty hard to fight a growing problem, which is victimizing a lot of PEOPLE and businesses!

Calgary Police press release, here.

Tuesday, March 06, 2007

Ruby Tuesday serves a blow to credit card skimmers

Ruby Tuesday is doing something about credit card fraud. They announced yesterday that they will be introducing an ultra-secure (encrypted) credit card system to protect their customers from fraud.

The AP is reporting:

The system, which is expected to be in all the restaurant chain's 900 locations by April, leaves no credit card information at the restaurant and is instead sent to the bank in encrypted form. The system is said to help prevent identity theft.
Criminals (some say of the organized type) have been targeting a lot of unprotected information, recently. Some of this information is bartered in underground chat rooms set up for this purpose.

Of note, Visa International commented that the new system is fully compliant with PCI data protection standards.

AP story, here.

If you would like to see the sheer volume of recent data breaches, Attrition.org has a chronology, here.

If you would like to see how easy it is for your payment card information to get skimmed at a restaurant - you can view an interesting video, here.

Wednesday, February 07, 2007

Is tracking fraudulent refund information effective and could it be putting people at risk of becoming an identity theft victim?

The retail industry loses billions of dollars a year to fraudulent refunds.

Fraudulent refunds occur when retail crooks (shoplifters, bad check writers and credit card fraudsters) bring in stolen merchandise to convert into cash. To protect themselves, merchants have developed refund policies, which require that personal information be maintained in a database to identify retail crooks.

I believe the merchants, who came up with this idea, did so with honorable intentions. But is it possible that these systems are easily defeated and themselves might be attacked (hacked) for information they are storing?

The retail security industry has a new buzz word (organized retail crime). If these crooks are organized, my guess is that they are already using fake identification and other people's identities to return merchandise.

Refund data-bases might be full of information from some of the other data-breaches. Other people's information is used to commit a lot of credit/debit card and check fraud. In the case of fraudulent transactions at retailers - the criminals often refund the merchandise they purchase (with bogus financial instruments) to get what they really want, or cash.

And it wouldn't be very hard for them to get bogus information - personal and financial information is for sale in carder forums and fake identification is getting better and easier to obtain all the time.

Another thing to consider is that besides organized retail criminals, another huge loss factor for retailers happens when insiders (dishonest employees) steal from them. Like the external element, a lot of dishonest employees seek to steal cash, and one of the easiest means to do so is to do fraudulent refunds, themselves.

Given the new refund systems, they will have to come up with an identity to accomplish this. The easiest way to do this is to use a customer already in one of their data-bases, or even make up a name.

TJX (a merchant operating under many different names) recently enabled what a lot of experts believe will be the largest data breach to date. One of the databases compromised was their information on all the people, who had refunded merchandise at their stores.

Unfortunately for TJX and the retail industry - it now appears they were storing financial information that they shouldn't have been.

According to reports, TJX was storing payment card (credit/debit card) information they weren't supposed to be in violation of already established PCI data-protection standards. These standards are established by the payment card industry, themselves.

It seems odd to me that in light of all the data breaches, the industry is being allowed to police themselves. I wonder if an unbiased third-party (with no financial incentive) should be taking a look at the problem?

And even if the merchants bring their data protection standards up-to-par for payment cards - will the data being mined in the refund systems receive similar protection?

Guard My Credit File.org recently published a story about Federated requiring SSNs for refunds (courtesy of a blog post and later conversation with George at Fat Pitch Financials).

Apparently George's wife bought some merchandise off one of their websites with a gift card. She decided to return the jeans (for credit back to her gift-card) and when she went into a Federated store (Macys), she was asked for her driver's license and SSN to complete the transaction.

Please note, she had her gift-card and the receipt for her purchase. George eventually complained loudly enough that a manager relented and allowed the return without a SSN.

My guess is that criminals are furnishing fake SSNs (which are hard to verify) and only the honest customers are providing real ones.

Story, here.

As I stated earlier, tracking refund data was probably a good idea when it was first conceived, but I wonder how effective it is today? The data itself could be posing risks to anyone honest enough to give their real information, and criminals are likely using other people's information.

Sadly enough, recent data- breaches indicate that this (personal information) probably isn't very well protected. It's also sad that after spending millions of dollars to protect themselves with refund databases, the retailers have a product that might not be very effective and could become a customer trust issue.

There needs to be a better way to protect merchants and their customers from theft. Customers and retailers are both being victimized by what seems to be a growing problem.

Here is another post, I wrote on this same issue:

Are Retail Refunds Violating Customer Privacy

Saturday, January 20, 2007

TJX named as point-of-compromise in International data breach - millions of people at risk!

Data breaches are happening at an alarming rate. Until some meaningful action is taken to address them, such as following already established principles (data and PCI security compliance), we're probably going to see them continue.

Reuters is reporting (courtesy of the Washington Post):

TJX said the breach involves the computer network that handles credit card, debit card, check and return transactions at its T.J. Maxx, Marshalls, HomeGoods and A.J. Wright stores in the United States and Puerto Rico; and its Winners and HomeSense stores in Canada.

It said the intrusion could also affect customers at stores in the United Kingdom and Ireland, and its Bob's Stores in the United States.
Reuters story, here.

This time not only credit and debit-card information was compromised, but check and all the personal information gathered when someone makes a refund might have been exposed, also.

The breach - reported to have been discovered in December - was kept quiet at the request of law enforcement.

The company has set up hot-lines, which are 866-484-6978 in the United States, 866-903-1408 in Canada and 0800-77-90-15 in the U.K. and Ireland. I called one of them and they didn't seem to be able to answer much, but told me if I wanted more information to go their website, here.

The problem in these large data breaches at merchants (TJX isn't the only one) is that too much personal and financial information is being maintained in databases, which aren't protected properly.

The Privacy Right's Clearinghouse maintains ample evidence of this, here.

The Payment Card Industry has already established data security standards, which aren't being followed in a lot of cases. Visa did a press release announcing that they are offering financial aid to Level 1 and Level 2 merchants. There is also mention that fines will be increased for merchants who fail to comply.

Unfortunately, even Visa states that compliance for Level 1 merchants is at 36 percent and 15 percent for Level 2 merchants.

Although, I commend the action by Visa, I fear fining non-compliant entities might not be enough.

Tech Web's "Dark Reading," has an excellent essay on the need to become more proactive, here.

In their essay, they state:
One recommendation is that Congress pass a law that compels organizations to protect sensitive information rather than one that simply determines when and how customers will be notified after the fact. There's been a consensus in Congress that standards are needed to safeguard personal information, but there's been a lack of unanimity in the details of how this should be done, says, Liz Gasster, acting executive director and general counsel for the Cyber Security Industry Alliance. "It was a real letdown for the citizens of this country that legislators weren't able to overcome their differences last year and pass a law," she says, adding that one big sticking point was Congress not wanting IT security improvements to create additional costs for industries operating in their constituencies.
Maybe with a new Congress, we'll see some "forward thinking" on this issue? After all, it's their responsibility to represent the people, who are having their personal and financial information compromised.

It would also be nice to see more funding to go after the criminals behind this growing problem. After all - the companies being breached aren't the source of this issue.

And besides enacting legislating and prosecuting the criminals doing this, we have the matter of "trust" and "consumer confidence" to consider. These are two "key" business principles that fuel economies. Failure to do something now; might lead to some unfortunate consequences, later.

If you would like to learn more about payment card compliance and data security, here's a site I recommend:

PCI and Data Security Compliance

Here's a previous post, I wrote on this subject:

With all the data breaches - something needs to be done!

Sunday, January 07, 2007

With all the data breaches - something needs to be done!

There have been a lot of large data breaches in the past year, where anonymous sources pointed to a retailer (merchant) as the point-of-compromise. Of course - as in most data breaches -rumors are often "downplayed" and in some instances, denied.

Card processors have been accused of maintaining information they shouldn't have, also.

The Privacy Rights Clearinghouse maintains a chronology of these incidents data breaches since 2005, which can be viewed, here.

And a business would have good reason not to disclose everything. It could create a lot of negative publicity, which would have a negative impact on their bottom line.

This is probably one of the better arguments for legislation requiring full disclosure, when people's personal information is compromised.

Could it be that a lot of these data breaches are being enabled by storing too much information in point of sale systems, which is poorly protected, and therefore - easily compromised (hacked) by criminals?

Last month, Visa International issued a press release offering $20 million in incentives to what they term Level 1 and Level 2 merchants to assist them in becoming compliant with the existing standard. It also mentions sanctions (fines) that will be imposed on merchants, who decide they aren't going to conform.

The press release states:

Locking down cardholder data is an important security component that will benefit financial institutions and merchants, and is equally important to maintain consumer trust in Visa," said Michael E. Smith, senior vice president of Enterprise Risk and Compliance at Visa USA. "By combining both incentives and fines, we expect acquirers to increase their efforts with merchants to accelerate their progress toward becoming PCI compliant and eliminating the storage of sensitive card data. Nothing is more important to Visa than securing commerce."

According to the press release, "current PCI compliance among Level 1 merchants is at 36 percent and 15 percent among Level 2 merchants, with the majority in both levels actively working toward compliance."

The bottom line is that it appears the card issuers (themselves) are getting pretty sick and tired of all the data breaches. My guess is that the banks -- who deal with the customer fall-out -- are getting pretty tired of it, also.

After one of the many posts, I've written about data breaches, I came into contact with a company called Security Metrics. Security Metrics provides a service to assist merchants in protecting their information.

Wen Free (Director of Business Development) told me that he believes breaches at the merchant level are becoming an "all too common" problem. Wen also told me that I would be shocked at how many merchants aren't in compliance, and are storing information - which isn't protected properly.

Wen pointed me to a tool developed by SecurityMetrics and MasterCard, where a business can run a Free-Scan (https://www.securitymetrics.com/eval_scan.adp) of their systems, to determine how compliant they actually are.

If these deductions are correct, it makes these merchants lucrative targets for hackers in search of people's financial information.

The fact that only 36 percent of the level 1 merchants and 15 percent of the level two merchants at Visa are "compliant" supports his contentions. And we have to remember that Visa isn't the only major issuer in the game and that most merchants offer multiple ways to pay for their goods and services.

With all the recent large-scale attacks on payment systems, it's going to be harder and harder for businesses to absorb losses from data breaches. Recent stories of carder forums - where this information is bought and sold on the Internet - point to the fact that there seems to be an abundance of (already breached) information available.

How the losses are allocated is normally kept pretty quiet, but my guess is that if the banks can charge back a merchant, they are doing so. But if the truth were to be told, these losses are eventually being charged back to all of us in the form of higher prices.

There are also customers stating that their fraud claims have been denied, and they are stuck with the loss. This can be especially true with debit-cards, if the loss isn't reported promptly.

Should everyone involved fail to solve this problem by themselves, my guess is that legislation will be the next step. After all, one of the most important asset in any business is the "trust and confidence" of their customers.

Here is a previous post, I wrote on this subject:

Is it a Lack of Security at Retailers Causing the Debit/Credit Card Breaches?

Monday, October 23, 2006

Romanian Illegal Immigrants Install ATM (Fraud) Machines

(Older picture of a skimming device)

Illegal immigration isn't a "victimless crime" and the work they are performing doesn't always help the economy. Apparently Romanian illegal immigrants are installing fake ATM fronts - used to steal debit-card details - for the very same criminal organizations that helped them get into the United Kingdom, illegally.

Justin Penrose of the Sunday Mirror (UK) is reporting:

They have developed a high-tech ATM front which looks exactly like the original - and it steals a victim's details in seconds.

The new cashpoint fascia is so convincing that gangs are selling it to other crooks for £10,000 a time.

The covers even have a sticker which warns customers to watch out for fraudsters. When a victim uses an ATM it records details while a camera videos the pin number. Within seconds these details are sent to a laptop and a cloned card is made. Several wealthy Romanian "godfathers" run crooked empires from their mansions in the Balkans.

Sunday Mirror story, here.

The article also states that these new and very convincing ATM fronts are being produced and sold to other criminal organizations.

I wonder how long it will be before this new "skimming device" is exported from the United Kingdom? In the past couple of years, debit-card fraud has become a worldwide problem.

This reminds me that the best defense against ATM skimming is to always cover your PIN when doing a transaction!

Here is a previous post about the growing problem of debit-card fraud:

Debit Card Breaches, A Growing Problem

And here is an older post, I did (with pictures) of a skimming device:

ATM Machines That Clone Your Card

If anyone has a picture of one of these new devices, please send it to EdwardDickson@SBCGlobal.net.

Thursday, October 19, 2006

How a Merchant Can Protect Their Customer's Personal and Financial Information

Visa and the U.S. Chamber of Commerce issued a report on the leading causes of data-breaches.

Here are the top five reasons:

Storage of mag stripe data - The most common cause of data breaches occurs when a merchant or service provider stores sensitive information encoded on the card's mag stripe in violation of PCI. This can happen because a number of POS systems improperly store this data, and the merchant may not be aware of it.

Missing or outdated security patches - In this scenario, hackers are able to penetrate merchants' or service providers' systems because they have not installed up-to-date security patches, leaving their systems vulnerable to intrusion.

Use of vendor supplied default settings and passwords - In many cases, merchants receive POS hardware or software from outside vendors, which install them using default settings and passwords that are often widely known to hackers and easy to guess.

SQL injection - Criminals use this technique to exploit Web-based applications for coding vulnerabilities and to attack a merchant's Internet applications (e.g. shopping carts).

Unnecessary and vulnerable services on servers - Vendors often ship servers with unnecessary services and applications enabled, although the user may not be aware of it. Because the services may not be required, security patches and upgrades may be ignored and the merchant system exposed to attack.

Ironically, merchants attempting to protect themselves from fraud (chargebacks) can end up compromising their customer's information by storing "unnecessary and sensitive" data.

Here is what they recommend doing to protect systems from being breached:

Ask their POS or payment software vendor (or reseller/integrator) to confirm their software version does not store mag stripe data, CVV2, PINs or encrypted PIN blocks. If it does, they should have these elements removed immediately.

Ask their payment software vendor for a list of files written by the application and a summary of the content to verify prohibited data is not stored.

Review custom POS applications for any evidence of prohibited data storage. Eliminate any functionality that enables storage of this data.

Search for and expunge all historical prohibited data elements that may reside within their payment system infrastructure.

Confirm that all cardholder data storage is necessary and appropriate for the transaction type.

Verify that their POS software version has been validated as compliant with the Visa Payment Application Best Practices. A list of PABP-compliant applications is available at www.visa.com/cisp

According to Visa:

"Merchants are permitted to store only specific data elements from the mag stripe to support card acceptance, according to Visa. This data includes cardholder's name, primary account number, expiration date and service code. However, merchants should store this data only if needed, and they must protect it as required by the Payment Card Industry (PCI) Data Security Standard."

Green Sheet article, here.

More good information on this from the U.S. Chamber of Commerce, here.

If anyone is interested in the number of data breaches recorded recently by the Privacy Rights Clearinghouse (which makes this information relevant), click here.

Data breaches are bad publicity for merchants and they damage the people that support their businesses (customers).