• On TV.com: THE GIRLS NEXT DOOR photos
October 9, 2008 4:37 PM PDT

High-tech bank robbers phone it in

Posted by Robert Vamosi
  • Print

Your ordinary bank robber can now steal hundreds of account numbers from ATMs without so much as lifting a finger. Instead, he skims.

Skimming is the physical use of secondary readers to capture the magnetic tracks on the backs of credit and debit cards. On ATMs, skimmers and secondary keypads are used to capture account numbers and PINs. Often, the ATM transaction goes through, and the customer doesn't realize that the account has been compromised until later.

Two risks these high-tech criminals face are being caught fitting a faux cover over an ordinary ATM card slot and keypad, then later retrieving the skimmers in order to get the account information.

With the arrest last week of "Chao," a Turkish ATM skimmer, comes new information on the lifestyles of modern bank robbers, including details on new devices that send captured account data via SMS to their smartphones.

For about $8,000, skimmers can have their own ATM overlay capable of transmitting 1,856 cards via SMS. Bulk pricing is available. And if they don't want the information sent card by card, they can dial into the device and download the data at their convenience.

You're probably saying, "wait, I'd notice the compromise." Not so fast. These guys are good. Very good. See the photos of a compromised ATM machine on Snopes.com. Or watch this video to see how ATM skimming with SMS was accomplished last year in Pennsylvania.

Skimming got its start in South Africa, and since 2004, there have been a handful of noteworthy cases in the United States, affecting ATMs in Seattle, San Francisco, Los Angeles, and Austin, Texas. Late last year, Citibank replaced debit cards for its Manhattan customers because of a skimming operation there.

Last February, during a presentation by Billy Rios and Nitesh Dhanjani at the Black Hat conference in Washington, I saw a photograph of a warehouse full of ATM card input overlays from one of the criminal enterprises they stumbled upon. You want black? They got black. You want beige? They have that. What about white or gray? Covered.

Industry standardization of ATM readers makes it easier for criminals to copy, so a bank robber needs only to match the look and style. A second photo showed boxes of keypad overlays. Large. Small. Again, you need only to match the look and style.

Once the account information is captured, the criminals tend to burn it onto blank magnetic stripe cards (ISO standard 7810), then use it at ATMs worldwide.

How are they able to fool so many people? In a blog on ZDNet, Dancho Danchev speculates that there might be some collusion with individuals working with ATM manufacturers. His blog is full of details from a site offering these overlays.

There is a downside to having the SMS service. As with a cell phone, the devices need batteries, which wear out. And some SMS transmissions simply fail. Still, if a criminal gets 1,500 bank account numbers, I don't think they're going to mind.

Recent posts from Defense in Depth
How to handle ID fraud's youngest victims
Is white listing going mainstream?
How Live OneCare changed the antivirus landscape
Express Scripts clients threatened with extortion
Study: DDoS attacks threaten ISP infrastructure
Add a Comment (Log in or register) 10 comments
by Michichael October 9, 2008 5:36 PM PDT
Scary stuff. It's shocking to see what some hackers can do now adays. I've seen hacks that exploit vulnerabilities in nVidia motherboards to change BIOS settings - including overclocking and voltage in some nTune capable boards. Long and short of it, a hacker could theoretically overvolt your memory, processor, whatever, and destroy physical components of ones computer.
Reply to this comment
by rdidit October 9, 2008 6:23 PM PDT
Clever, these thieves, and the bleeding heart liberals criminal prosecutions bleat leniency. I say the guilty go to jail forever.
Reply to this comment
by The_Decider October 24, 2008 4:29 PM PDT
I say that straw man abusers should go to jail forever.
by JaquesLenoir October 10, 2008 2:08 AM PDT
Hello!!! Still using magnetic cards where the rest of the world is using the "Smart Cards". Just got what you deserve for using such obsolete technology.

F.
Reply to this comment
by patch991 October 10, 2008 8:14 AM PDT
A$$!
by The_Decider October 24, 2008 4:28 PM PDT
Yeah, because is it harder to get information off of a smart card.

Oh wait, it is just as easy.
by davidsmi October 10, 2008 6:16 AM PDT
WOW - Canada is very advanced - our criminals have been doing this for years!

I guess the cost of the loss is less then the cost of smart cards - hard to belive!!!
Reply to this comment
by Maarek Stele October 10, 2008 8:39 AM PDT
Only use your bank. Almost ALL places use credit/debit cards.

I always test the system with my AAA card which will open any ATM door because they only require a magnetic strip. Now I've used MY ATM many times and all the branches have the same machine. If it's different I DON'T USE IT.

It's that simple.

This isn't scary, it's common sense.

I've seen scammers put up signs saying "swipe to clean your card" when it's actualy a recorder. It's just COMMON sense people.

If you're not sure, than your right and DON'T use it!
Reply to this comment
by shinycars October 14, 2008 1:20 PM PDT
We need to use an INDIVIDUAL FINGERPRINT for all ATM, CC or Debit Card transactions -- Problem Solved. This is already being done in parts of Europe. It costs $ to implement it and I've heard the American banks and CC's dont want to pay it. But....an extra $850 Billion showed up recently. Seriously this is the simple and effective answer to all this fraud, ID theft, etc.
Reply to this comment
by The_Decider October 24, 2008 4:31 PM PDT
Fingerprint scanners are not foolproof. There are ways of using the fingerprint of the person who used it before you.

Fingerprints get digitized that means it can be spoofed.

Biometrics is a false security blanket.
advertisement

In the news now

Apple's iPhone 2.2
hits the street

The latest software update offers several improvements to Google maps as well as wireless downloading for podcasts.



The big chill for holiday parties?

Tech companies faced with cost-cutting may not be canceling the annual festivities outright, but things are certainly being done differently this year.



About Defense in Depth

Covering computer viruses and computer crime, Robert Vamosi goes beyond the hype to provide you with expert interviews of the top security researchers, as well as offering the hands-on, nontechnical advice you'll need to stay safe online.

Add this feed to your online news reader

Defense in Depth topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right