Pages

Showing posts with label Hacked. Show all posts
Showing posts with label Hacked. Show all posts

Tuesday, February 1, 2011

How I Got My ATM Card Skimmed


On Sunday June 27th, 2010 at around 2:00pm I took out $200 dollars from my local branch ATM.  Little did I know that this ATM had been compromised and was fashioned with an ATM skimmer. The compromised ATM was within the bank and wasn’t your normal outdoor ATM unit. After using the ATM, my card information and pin number were successfully stolen and I was completely unaware of the theft. I left the ATM with my $200 dollars without thinking twice.
Monday June 28th, 2010 at around 6:00pm I received a call from my bank’s fraud department asking if I had made 2 withdrawals in Manhattan within the past 24 hours for a total of $600 dollars. I told the analyst on the phone that I hadn’t been in Manhattan that weekend, and to please put a hold on my card. The analyst then explained to me that my card had been compromised and that they were cancelling the card. She explained to me that I would have to go down to a local branch and receive a new one. At this point she started the process of refunding my account and gave me a case and telephone number to follow up with in the morning.
Tuesday June 29th, 2010 at around 10:00am I called the number the fraud analyst gave me and spoke with the fraud department again. I explained what happened and they refunded me the money that was stolen. They then asked me a few questions on what I was doing that weekend and if I’d like to press charges or file a police report if needed; I told them that I would. After getting off the phone I went directly to my local branch to get a new debt card, not knowing that this was the site of the compromised ATM. When I arrived I spoke with the bank manager and told her what had happened. She asked me if I had used their ATM over the weekend, and after I told her I did she told me to take a seat in the lobby with a few other people that also had their cards compromised. I was the 7th user that morning that they were dealing with regarding their compromised ATM. She explained to me that they found the skimmer earlier and had removed it from the ATM. I went through the process of creating a new card and pin number on-site at the branch.
Monday January 17th, 2011 I received a letter in the mail from the U.S Department of Justice regarding the 5 defendants, all of Romanian decent, that were in custody regarding my case. This was the first correspondence regarding this case since the day I received my new debt card. The document showed the 5 names of the defendants that were in custody and gave me a case number, court docket number, a victim ID number and a pin. Also on the document were a website www.notify.usdoj.gov and the phone number of the Victim Witness Coordinator. Here you could use the victim ID and pin number to get details regarding court dates, arrests and charges.
After calling the number I was able to determine that only two of the defendants were still in custody with no scheduled court dates assigned to them. The charges being brought against them were as follows: 2 counts of Bank fraud, 1 count of Fraud Related Activity: Identification Documents, and 2 counts of Fraud Related Activity: Access Device. They were arrested on October 27th, 2010, exactly four months after skimming my card. 
A few things I learned from this experience are  never trust an ATM or device that you have to insert your card and pin number into. Cyber thieves are making such slick devices now that you won't even notice the skimmers. Many times criminals have replaced hardware or implanted devices into ATMs or gas pumps, some with cellular technology included (http://www.frontlinesentinel.com/2011/01/ultimate-post-about-atm-skimmers.html). This doesn't leave the consumer a chance, so don't be embarrassed. Also it seems like the banks are getting much more aggressive about catching the bad guys, which is a good thing, but the bad guys always seem to be one step ahead. For now.

Saturday, January 8, 2011

The Building Cyber Threat Of Mobile Phones

As mobile phone users continue to grow exponentially every year, the threat of malicious intent involving smart phones increases as well. With the emergence of Google's Android OS appearing on multiple vendor phones, its only a matter of time before there's a major breach involving a major smart phone distributor.

Over the past year there's been multiple instances of malicious apps being downloaded from the Android Market onto a users phone, using simple social engineering tactics (I.E New Angry Bird Levels, Twilight app, etc.) that are all designed for information stealing, service theft or botnet creation. Some of these apps have the potential to steal information such as contacts, send out SMS texts, make phone calls and determine your location via the built-in GPS. These apps could theoretically be installed from any vendor store, but its more likely to be installed on an Android OS since they don't vet their apps as throughly, if at all before being placed on their "Market".   http://www.informationweek.com/news/security/vulnerabilities/showArticle.jhtml?articleID=228200946

Most major vendors like Apple and Google have something called a "Kill Switch", that will allow the app to be removed globally across all phones that have it installed. Once an app has been determined to have breached
the vendors policy they'll push the button and have it killed. Its not sure if the users will have the money reimbursed for the purchase of the app after its been killed. http://www.informationweek.com/news/internet/google/showArticle.jhtml?articleID=211200988

Certain banking apps have also been compromised with "Man-in-the-browser" like attacks that end up stealing banking credentials that give attackers access to your banking credentials and account information. http://threatpost.com/en_us/blogs/zeus-variant-targets-mobile-online-banking-apps-092710

Right now there are a few vendors that are creating anti-virus for phones, but I don't think this is the road we should take considering that anti-virus isn't working now for PCs. http://usa.kaspersky.com/products-services/home-computer-security/mobile-security

All mobile phone users should not only password protect their phones, but they should encrypt the data that's stored on it. Both of these are simple settings that can be enabled on the majority of phones. This and using caution when downloading applications will prevent malicious activity on your phone for now.