• On TV.com: THE GIRLS NEXT DOOR photos
October 9, 2008 4:37 PM PDT

High-tech bank robbers phone it in

Posted by Robert Vamosi
  • Font size
  • Print

Your ordinary bank robber can now steal hundreds of account numbers from ATMs without so much as lifting a finger. Instead, he skims.

Skimming is the physical use of secondary readers to capture the magnetic tracks on the backs of credit and debit cards. On ATMs, skimmers and secondary keypads are used to capture account numbers and PINs. Often, the ATM transaction goes through, and the customer doesn't realize that the account has been compromised until later.

Two risks these high-tech criminals face are being caught fitting a faux cover over an ordinary ATM card slot and keypad, then later retrieving the skimmers in order to get the account information.

With the arrest last week of "Chao," a Turkish ATM skimmer, comes new information on the lifestyles of modern bank robbers, including details on new devices that send captured account data via SMS to their smartphones.

For about $8,000, skimmers can have their own ATM overlay capable of transmitting 1,856 cards via SMS. Bulk pricing is available. And if they don't want the information sent card by card, they can dial into the device and download the data at their convenience.

You're probably saying, "wait, I'd notice the compromise." Not so fast. These guys are good. Very good. See the photos of a compromised ATM machine on Snopes.com. Or watch this video to see how ATM skimming with SMS was accomplished last year in Pennsylvania.

Skimming got its start in South Africa, and since 2004, there have been a handful of noteworthy cases in the United States, affecting ATMs in Seattle, San Francisco, Los Angeles, and Austin, Texas. Late last year, Citibank replaced debit cards for its Manhattan customers because of a skimming operation there.

Last February, during a presentation by Billy Rios and Nitesh Dhanjani at the Black Hat conference in Washington, I saw a photograph of a warehouse full of ATM card input overlays from one of the criminal enterprises they stumbled upon. You want black? They got black. You want beige? They have that. What about white or gray? Covered.

Industry standardization of ATM readers makes it easier for criminals to copy, so a bank robber needs only to match the look and style. A second photo showed boxes of keypad overlays. Large. Small. Again, you need only to match the look and style.

Once the account information is captured, the criminals tend to burn it onto blank magnetic stripe cards (ISO standard 7810), then use it at ATMs worldwide.

How are they able to fool so many people? In a blog on ZDNet, Dancho Danchev speculates that there might be some collusion with individuals working with ATM manufacturers. His blog is full of details from a site offering these overlays.

There is a downside to having the SMS service. As with a cell phone, the devices need batteries, which wear out. And some SMS transmissions simply fail. Still, if a criminal gets 1,500 bank account numbers, I don't think they're going to mind.

Recent posts from Defense in Depth
How to handle ID fraud's youngest victims
Is white listing going mainstream?
How Live OneCare changed the antivirus landscape
Express Scripts clients threatened with extortion
Study: DDoS attacks threaten ISP infrastructure
Security expert talks Russian gangs, botnets
Extortion used in Express Scripts database breach
WPA wireless encryption cracked
Add a Comment (Log in or register) 10 comments
by Michichael October 9, 2008 5:36 PM PDT
Scary stuff. It's shocking to see what some hackers can do now adays. I've seen hacks that exploit vulnerabilities in nVidia motherboards to change BIOS settings - including overclocking and voltage in some nTune capable boards. Long and short of it, a hacker could theoretically overvolt your memory, processor, whatever, and destroy physical components of ones computer.
Reply to this comment
by rdidit October 9, 2008 6:23 PM PDT
Clever, these thieves, and the bleeding heart liberals criminal prosecutions bleat leniency. I say the guilty go to jail forever.
Reply to this comment
by The_Decider October 24, 2008 4:29 PM PDT
I say that straw man abusers should go to jail forever.
by JaquesLenoir October 10, 2008 2:08 AM PDT
Hello!!! Still using magnetic cards where the rest of the world is using the "Smart Cards". Just got what you deserve for using such obsolete technology.

F.
Reply to this comment
by patch991 October 10, 2008 8:14 AM PDT
A$$!
by The_Decider October 24, 2008 4:28 PM PDT
Yeah, because is it harder to get information off of a smart card.

Oh wait, it is just as easy.
by davidsmi October 10, 2008 6:16 AM PDT
WOW - Canada is very advanced - our criminals have been doing this for years!

I guess the cost of the loss is less then the cost of smart cards - hard to belive!!!
Reply to this comment
by Maarek Stele October 10, 2008 8:39 AM PDT
Only use your bank. Almost ALL places use credit/debit cards.

I always test the system with my AAA card which will open any ATM door because they only require a magnetic strip. Now I've used MY ATM many times and all the branches have the same machine. If it's different I DON'T USE IT.

It's that simple.

This isn't scary, it's common sense.

I've seen scammers put up signs saying "swipe to clean your card" when it's actualy a recorder. It's just COMMON sense people.

If you're not sure, than your right and DON'T use it!
Reply to this comment
by shinycars October 14, 2008 1:20 PM PDT
We need to use an INDIVIDUAL FINGERPRINT for all ATM, CC or Debit Card transactions -- Problem Solved. This is already being done in parts of Europe. It costs $ to implement it and I've heard the American banks and CC's dont want to pay it. But....an extra $850 Billion showed up recently. Seriously this is the simple and effective answer to all this fraud, ID theft, etc.
Reply to this comment
by The_Decider October 24, 2008 4:31 PM PDT
Fingerprint scanners are not foolproof. There are ways of using the fingerprint of the person who used it before you.

Fingerprints get digitized that means it can be spoofed.

Biometrics is a false security blanket.
advertisement

In the news now

Slowing expectations at a green-tech start-up

Six months ago, biofuels start-up Mascoma had the wind in its sails, as did the rest of the clean-tech sector. Now, the company is treading carefully and scaling back.


With JavaFX, Sun seeks new coders, new revenue

With the launch of JavaFX 1.0, Sun is trying to reclaim Java's strength as a foundation for rich Internet applications. But it's no longer the incumbent.


Tim Lincecum, motion capture star

San Francisco Giants pitcher, who won the Cy Young award last month, dons a motion capture suit for 2K Sports' Major League Baseball 2K9 video game.


About Defense in Depth

Covering computer viruses and computer crime, Robert Vamosi goes beyond the hype to provide you with expert interviews of the top security researchers, as well as offering the hands-on, nontechnical advice you'll need to stay safe online.

Add this feed to your online news reader

Defense in Depth topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right