Wednesday, January 21, 2009
Will Heartland Become the Largest Data Breach in History?
Heartland was initially notified by Visa/Mastercard of suspicious activity, which led to malicious software being discovered in their system. The malware in question was harvesting and (obviously) transmitting data. In the press release, they state they believe the breach has been contained. Heartland claims no merchant data, social security numbers or unencrypted PINs were compromised. They were also quick to add that their check management systems, Canadian payroll, campus solutions, micropayments operations and recently acquired Network Services and Chockstone processing platforms had not been compromised, either.
It should be noted that in previous breaches, additional items were later discovered to have been compromised as the investigation progressed.
Brian Krebs at the Washington Post interviewed Robert Baldwin, Heartland's president and chief financial officer, who stated they don't know how many transactions were compromised. In the interview, Baldwin pointed out that since the card numbers compromised didn't have address information; it would be hard for fraudsters to use them in card-not-present (e-commmerce) transactions. Most e-commerce platforms validate the address tied to the card as a security measure. I thought about this for a second and remembered that Visa/Mastercard had warned Heartland about suspicious transactions. If there were suspicious transactions, I would deduct someone is using this data to commit fraud. Besides that, I doubt anyone sophisticated enough to pull this off would go to all this trouble (and potential legal exposure) if they couldn't use the information to make money. This is another thing that might suggest additional information will be discovered as the investigation progresses.
In the interview, Baldwin declined to name any of their customers, who were compromised. Heartland processes payments for about 250,000 customers and processes about 100 million transactions per month. He also said they will not be offering identity theft protection since not enough information was stolen to commit identity theft.
On the Truston blog, Tom Fragala, aptly pointed out that this equates to four billion transactions a year. Many are speculating that this will turn out to be the largest known data breach in history. Tom's company, which offers a privacy-friendly identity theft prevention and recovery service, offers a 45 day free-trial of their services. Even after the 45 days, the prevention part of the service is free.
Tom blogs on matters like this and wrote an interesting article pointing out the consumer protection features of debit and credit cards. Please note, debit cards offer less protection. The point is that if a card owner doesn't discover the fraud in a specified time period, they can be held liable for the financial loss. It's probably a good time for everyone to pay attention to their statements, carefully.
Given the mandatory notification laws, which have been passed in almost all 50 states, this is going to equate a lot of people that have to be notified. Simply stated, it's going to be a "notification nightmare." It should be noted that shutting down all the compromised cards and notifying victims is a substantial cost in any data breach.
SC Magazine also covered the story and got a quote from Rich Mogull, founder of IT security consultancy Securosis, who pointed out there is a trend of malicious software being planted somewhere in the processing system in all the high-profile data breaches seen in recent history. TJX (94 million cards compromised), Hannaford and CardSystems (40 million cards compromised) are all being cited as examples.
According to Visa, Heartland was validated as Payment Card Industry Data Security Standard (PCI DSS) compliant on April 30, 2008. They then stated this status was being reviewed. Trustwave is Heartland's PCI assessor. Hannaford was PCI compliant at the time they were compromised, also. According to the article in SC magazine, TrustWave wouldn't return calls to comment on this.
On the Heartland site, it mentions they are a founding supporter of the Merchant Bill of Rights, which advocates for and educates merchants on fair practices when they accept payment cards. Two of the biggest heartaches for merchants accepting payment cards are the interchange fees and becoming PCI compliant, which is considered an expensive process. Interchange fees are a tariff charged by the credit card companies on every transaction and according to the critics are not very equitable. Estimates have been made in the past that they equate to $30 billion in extra fees added to the cost-of-goods sold with payment cards, yearly. Ultimately, these are costs are often passed on to the consumer.
So far as PCI compliance — which now seems to have been proven ineffective in at least two instances — the National Retail Federation has responded by going on record to challenge the card issuers on their requirements to store data. Because of the cost, a lot of merchants have been slow to adopt PCI data-security standards and the merchants who are not in compliance face fines by the payment card industry.
Storing this data is required to prevent the third headache merchants face when accepting payment cards, or what is known as chargebacks. Chargebacks are when transactions are charged back to a merchant account because of alleged fraud. The NRF contends that being forced to maintain the data to protect themselves makes it easier to compromise.
Heartland is being challenged for releasing this information during the inauguration, when it was less likely to be a hot story. Although this seems to be the case, we need to realize the stakes in data-breaches are high. In the last breach involving a card processor (CardSystems), the card-issuers stopped doing business with the company and the end-result was the company is no longer in existence. Also, it should be pointed out that Heartland wouldn't be the only company that seemed to be very cautious when disclosing the fact that their data was compromised. Once disclosed, there is little doubt that the company in question faces some extremely unfavorable public exposure.
On a closing note, data breaches continue to occur at alarming rates. All sides of the equation need to come together and figure out solutions that work. One of them might be to upgrade the plastic to chip and PIN technology, which has become the standard in other countries. Nigeria was the most recent country to mandate this technology. While this might not directly stop data breaches, it would make it a lot harder to counterfeit the plastic, which is what the criminals use to cash-out the proceeds of data breaches with.
The other problem is that credit card fraud has been made too easy to commit. Card data and the tools to produce counterfeit cards are easy to obtain and even sold in chat rooms. A lot of this technology can also be bought on (what I consider) questionable sites, including eBay. Very few of these fraudsters get caught and because of this; it appears that the activity is getting more and more organized. Historically, the cost of all this seems to have been written off as a cost of doing business. In reality, a lot of these "costs" are passed on to the consumer in the form of higher interest rates and fees.
My prediction is that with the state credit is currently in with the sour economy, coupled with the increase in criminal activity, we are getting to the point where it is going to be hard to simply write-off all the financial costs. Until we start punishing the criminals effectively for this type of activity, it is going to continue to grow and probably prosper.
Update 2/13/09: It appears that the first arrests in the Heartland Data Breach have been made in Leon County, Florida. Three men (Tony Acreus, Jeremy Frazier and Timothy Johns) were encoding numbers stolen in the breach on gift cards and using them at Walmart.
The official press release from the authorities credits Walmart for supporting the investigation.
While it's great a few people got caught -- this probably only accounts for a small amount of the stolen data. My guess is that our three fraudsters bought the numbers via anonymous sources (probably on the Internet).
Monday, January 19, 2009
Fake Obama Site is a Malware Booby-Trap
On Sunday, with the inauguration less than 24 hours away, I got a hot tip that the Symantec Lab had detected another round of Obama spam with malicious intent being sent across the electronic universe. Zuftikar Ramzan announced on the Symantec Security Blog that this latest round of Obama spam uses lures with titles like "Our new president has gone," "Obama refused to be the president of the United States of America," and "There is no president in the USA anymore and Obama has gone."
Zuftikar also mentioned a link in these e-mails (removed for safety reasons) leading to a faux website that looks amazingly similar to the official Obama-Biden site. The fake site can be seen below:

This fake site attempts to exploit weaknesses in a Web browser to install malicious software without the owner's knowledge. According to Zuftikar, the page and its links all have malicious software on them. In other words, the entire site is literally a virtual booby trap.
The files are titled usa.exe, obamanew.exe, pdf.exe, statement.exe, barackblog.exe and barackspeech.exe. While the titles might be different, they lead to the same variety of malware known as the W32.Waledac. This malicious software is capable of stealing sensitive information, turning your machine into a spam-spewing zombie and leaving a back door for a hacker to gain access to it.
Political themes have been used a lot in recent times to lure people into clicking on links in spam e-mails they shouldn't have. Other common lures include the old fashioned too-good-to-be-true, security and badge-of-authority types (IRS, FBI, CIA, etc.).
With tax season upon us, expect the IRS to be a common one used in the near future.Symantec does provide removal instructions for this malware on their site, but most of us are far better off by not clicking on this type of stuff in the first place. These e-mails are sent out by the millions and the best thing to do is hit delete before opening them up.
Saturday, January 17, 2009
Inauguration Security Sets a Record by Itself!
The security assets deployed for this event are so numerous, I had to read several mainstream news articles and press releases just to try to determine how many agencies were involved. Even after doing this, I would guess there are some that are not being publicly disclosed for good reasons.
Michael Chertoff, Homeland Security Secretary, will be on-hand himself and operating from a multi-agency command center. The command center will have representatives from 58 federal and local agencies. These representatives, who will all be in the same room, will give those involved in the event the ability to instantly communicate with each other.
The command center is live as of this writing and will remain in operation until 4:00 p.m. (Eastern Standard Time) on Wednesday. This is, of course, unless something happens and it needs to remain in operation longer.
Chertoff believes this will be the most complex security event ever mounted, but also mentioned to CNN that he is worried about the cold weather and the impact it might have on unprepared visitors. We need to remember that a lot of unfortunate things can occur when a mass of human beings gather. Unlike most of Bush's administration, Chertoff will remain on duty until after the inauguration is over.
An official press release from Secretary Chertoff, District of Columbia Mayor Adrian M. Fenty, Maryland Governor Martin O’Malley and Virginia Governor Timothy M. Kaine on the inauguration can be seen on the DHS site.
I found more information about inauguration security on the Secret Service site, which states that the FAA (Federal Aviation Administration) will be stepping up security on the air corridors around DC and the Coast Guard will patrol on the Potomac. It also mentions that the police involved will be from the Washington Metropolitan, Park and Capitol departments. If you are attending the event, or live in the area, it has a list of road closures that will be in effect during the inauguration.
The FBI is deploying lot of high-tech security devices including mobile command centers, mine-resistant ambush-protected vehicles, bomb containment vessels and bomb technician vehicles, which resemble a mobile-home.
Mine-Resistant Ambush-Protected Hummer
In addition to the high-tech specialty equipment being deployed by the FBI — they will have a SWAT Team, Hazardous Materials Response Team, Bomb Technicians, an Underwater Search and Response Team and Crisis Negotiators — at the ready to handle a crisis scenario.
The military personnel — who will be mostly National Guard troops because of a law that prohibits active duty personnel from engaging in domestic law enforcement duties — will have assignments in the events, also. These include providing bomb sniffing dogs, NBC (Nuclear, Biological and Chemical) teams, transportation and communications units.
According to all of the officials involved, there is no specific threat they are worried about. Although some of the pundits are complaining that the security for this event is too intense, the proof in the pudding will be allowing them to claim they were right after it is all over. If that is the case, nothing will have happened and these measures will have accomplished their goal!
Sunday, January 11, 2009
How Foreign Crime Gangs Establish Their Identities
The problem isn’t people trying to make a better life for themselves, the problem is that criminals are able to easily manipulate the security of our borders. There is even a good example in the story of how illegal immigrants are routinely victimized. In order to pay back their debt for being brought in illegally -- they were working in a sweatshop located in a middle-class residential neighborhood — producing counterfeits of designer labels.
On a side note, according to the International AntiCounterfeiting Coalition, counterfeit merchandise is a $600 billion a year problem in itself.
The story, written by Tom Jackman, of the Washington Post details an undercover investigation that starts with manipulating cigarette taxes and progresses into identity theft, mortgage fraud, money laundering, counterfeiting and even murder-for-hire.
The initial scheme with the cigarettes involved buying cigarettes in Virginia — which has a 30 cent per pack tax -- and transporting them to New York where the tax runs $4.25 a pack. Like the designer clothing being knocked-off (counterfeited), the tax stamps were counterfeited. According to an ATF agent quoted in the story, this equates to billions of dollars that have “gone missing” in tax revenue.
The identity theft and resulting crimes, such as mortgage and credit card fraud, were discovered when undercover agents were introduced to an individual selling social-security numbers and passport information obtained from Chinese nationals working in the Marianas Islands. This information was then used to establish credit and obtain identification to make the members of the gang appear to be legitimate members of our society.
The investigation also uncovered a dishonest DMV employee in Illinois, who was providing identification to members of the group. These documents were then traded in for identification from other States. In this case, the State was often Virginia. This sent shivers up my spine as I remembered that Mohammed Atta and crew used Virginia, Florida, New Jersey and California driver’s licenses' — which were obtained after they entered the country with counterfeit documents – to board the planes in what became 9-11.

In the past, I’ve written about and spoken to Suad Leija and her husband, who have been working with the government to expose a cartel that operates throughout the country providing counterfeit identification documents. They have dubbed these documents, “Paper Weapons” because they can be used to commit crimes or even achieve radical political objectives. Suad’s story has been covered in the mainstream media on a fairly regular basis. According to the conversations I've had with Suad and her husband, most of the people illegally entering the country use what are known as "feeder documents" to establish themselves. Their eventual goal is to establish an identity that appears to be as legitimate as yours or mine. Once they accomplish this, the identities can be used to establish credit and even get a mortgage.
In the Washington Post story, no mention of direct fraud involving a financial loss is mentioned. The intent seems to be to use the identities to establish a "seemingly" legal status and then commit other crimes. The story mentions that the group offered to help launder the illegal revenue being made from selling the cigarettes. This was done with personal and cashier’s checks, which suggests the identities were also used to open bank accounts.
These fraudulently established identities were also being used to buy real estate. Although no direct financial fraud is mentioned in the article, it wouldn’t be very hard for people doing this to get some home-equity loans, cash them out and disappear. They could do this if they were leaving the country, or simply move on to another identity and do it all over again. Given that we are in a pretty severe recession, sparked by a mortgage crisis, it again made me wonder how much of it might have been caused by fraud that we aren’t even aware of?
When the sweat shops were raided, crack pipes were found. This was probably to keep the people working in them in a state of addiction, which would assist in keeping them under the control of their keepers. Abuse of illegal immigrants is well-documented and this is probably only one of many examples going on throughout the country at this very moment. It isn’t unknown for illegal immigrants to be forced into smuggling drugs, committing financial crimes or even becoming prostitutes.
This is just one example, but a good one, of how insecure our borders really are. It also shows the more severe consequences of allowing identity theft to run rampant in our society. Now that the election is over, perhaps it’s time for our politicians to stop ignoring the problem. We are a nation of immigrants, and in the end, very few of us are against hard-working people trying to better themselves. The problem is that the way we currently approach the problem enables criminals (and potentially terrorists) to operate and profit at the expense of society.


