This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

PIN Scandal "Worst Hack Ever"...

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.techweb.com/article/printableAr…_section=700028
March 09, 2006
"The unfolding debit card scam that rocked Citibank this week is far from over, an analyst said Thursday as she called this first-time-ever mass theft of PINs "the worst consumer scam to date." Wednesday, Citibank confirmed that an ongoing fraud had forced it to reissue debit cards and block PIN-based transactions for users in Canada, Russia, and the U.K.
But Citibank is only the tip of the iceberg, said Avivah Litan, a Gartner research vice president. The scam – and scandal – has hit national banks like Bank of America, Wells Fargo, and Washington Mutual, as well as smaller banks, including ones in Oregon, Ohio, and Pennsylvania, all of which have re-issued debit cards in recent weeks. "This is the worst hack ever," Litan maintained. "It's significant because not only is it a really wide-spread breach, but it affects debit cards, which everyone thought were immune to these kinds of things." Unlike credit cards, debit cards offer an additional level of security: the password-like Personal Identification Number, or PIN. "That's the irony, the PIN was supposed to make debit cards secure," Litan said. "Up until this breach, everyone thought ATMS and PINs could never be compromised." Litan's sources in the financial industry have told her that thieves hacked into a as-yet-unknown system, and made off with data stored on debit cards' magnetic stripes, the associated "PIN blocks," or encrypted PIN data, and the key for that encrypted data.
The problem, she continued, is that retailers improperly store PIN numbers after they've been entered, rather than erase them at the PIN-entering pad. Worse, the keys to decrypt the PIN blocks are often stored on the same network as the PINs themselves, making a single successful hack a potential goldmine for criminals: they get the PIN data and the key to read it. In this case, Litan said, the thieves used the information to crank out counterfeit debit cards, then emptied accounts at ATMs. She estimated that they absconded with "at least a couple of thousand records, maybe more" and have cashed out to the tune of "millions already." The victim of the hack attack isn't yet known, although some banks have pointed fingers at OfficeMax, which has denied that its system was penetrated. Litan believes it much more likely that a third-party processor or terminal supplier was involved; the silence about the victim could point to a processor, she said, because they have the most to loose by the negative publicity. Last summer, credit card processor CardSystems was hit with a massive breach that involved millions of accounts; CardSystems essentially sank under the publicity, and was later bought by Pay By Touch. In February 2006, the FTC reached a settlement with CardSystems that require it to adopt more stringent security measures, but the company remains open to consumer lawsuits that could mean millions in payouts.
No matter who is to blame, the bank industry is only about halfway through cleaning up the breach, said Litan. And more of the same is on the way…"

:rant2:
FYI…

- http://www.silicon.com/financialservices/0…39157105,00.htm
10 March 2006
"A Citibank ATM network breach in Canada, Russia and the UK could have been prevented if the bank's US customers had chip and PIN technology on their cards, a leading analyst has said. Citibank this week admitted that hundreds of its US customers had been affected when hackers broke into the ATM network through a retail store server and stole a "block" of PINs and the keys to decrypt them. Avivah Litan, a research director for Gartner, told silicon.com: "You won’t have the same problem with a chip card. They are hard to duplicate but it's pretty easy to copy a magnetic stripe." With a PIN-block, hackers break into retailer servers and steal a chunk of PINs, then create counterfeit cards that enable them to withdraw cash at ATM machines. Litan wrote that in this case the thieves probably stole magnetic-stripe data found on the back of ATM cards. She said: "What's really exposed are the retail systems that use the ATM system. It could have been an insider – it's very hard to know. It was someone who had access to the [encryption] keys data. They were very skilled." The analyst said the crime reflects the largest PIN theft to date and the financial industry will be hit by more PIN-block fraud in the future… Citibank confirmed only US customers had been affected by the theft. It is now reissuing cards to customers whose accounts were blocked after the fraud was discovered. A spokesman for Citibank told silicon.com: "All this occurred because of a breach at a company in the US. There was a small proportion of customers who were affected. We are not aware of customers affected outside the US."

:(
FYI…

Visa warns software may store customer data
- http://news.com.com/2102-1029_3-6051261.ht…g=st.util.print
Mar 17, 2006
"A popular software that retailers use to control debit-card transactions may inadvertently store sensitive customer information, including PIN codes, says Visa. Two versions of cash-register software made by Fujitsu Transaction Solutions are under scrutiny, according to a warning Visa issued to the companies that process card transactions for some of the nation's largest retailers. A Visa representative confirmed that the warning was sent.
Some of Fujitsu's retail customers include Best Buy, Staples and OfficeMax, but it is not known which companies use the software Visa claims is flawed. Visa's warning, which was first reported by The Wall Street Journal on Friday, has raised eyebrows in the financial and retail sectors. The software was flagged at a time when thousands of debit-card holders across the country have reported unauthorized withdrawals from their accounts.
Bank of America, Washington Mutual and Citibank are among the financial institutions that have replaced more than 200,000 debit cards in the past two months and have told customers that thieves obtained vital debit-card information as a result of a security breach at a large merchant. One commonality among the fraud victims, according to law enforcement and banking officials, is that most had shopped at one of Fujitsu's clients: OfficeMax. The office-supply retailer has said that it has found no indication that it suffered an illegal intrusion. Fujitsu, which did not return repeated phone calls from CNET News.com on Friday, denied that its software has had anything to do with any alleged security breach. A representative for the company told the Journal that customer data, such as PIN codes, could not be stored using just its software. Other software tools would have to be added…"

:(
FYI…

- http://www.techweb.com/article/printableAr…_section=700028
March 20, 2006
"Visa confirmed Monday it has issued an alert warning that some point-of-sale software may be storing PINs in violation of industry rules, leading to suspicions that the root of the recent debit card debacle may have been out-of-date or misconfigured software. "….we provided a confidential alert to a limited number of financial institutions advising them that a particular configuration of certain software could cause it to store cardholder data," Visa said in a statement e-mailed to TechWeb. "We further advised them of the existence of a software upgrade designed to address the problem"…
The picture remains muddy, but circumstantial evidence seems to point toward a breach at a major retailer. Two weeks ago, Citibank – another financial institution that has had to re-issue large numbers of debit cards – said it had blocked access to ATMs in Canada, the U.K., and Russia because of fraud. At that time, Citibank said only that the breach occurred at a third-party, presumably a card processor or retailer…"

:(