Showing posts with label Skimming. Show all posts
Showing posts with label Skimming. Show all posts

Thursday, July 17, 2008

International Fraud Case Has Local Ties - kcra.com - 15 Jul 2008

Women Known As 'Richmond Girls' Arrested


RICHMOND, Calif. -- An international crime ring involving more than a $1 million worth of credit card fraud has ties to the Central Valley, police said.

Police arrested six women from the Bay Area who were allegedly targeting 10 Central Valley stores in a credit card fraud scheme.

Officials of the Sacramento Valley High Tech Crimes Task Force said the group of women, called the "Richmond Girls," are responsible for $1 million in fraudulent credit card transactions in the past six months.

The women allegedly used credit card encoders to recode gift cards that were used at stores like Target and Wal-Mart along Interstate 80 between Roseville and the Bay Area, police said.

Police said they think the women are somehow connected to Ukrainian and Russian identity theft rings, who would e-mail the women credit card account numbers stolen from at least 400 U.S. and foreign citizens, according to investigators.

"We definitely think the ring is bigger than six," said task force spokesman Sean Smith. "I don't want to give too many details since it's an active investigation, but it is a significantly larger number than six people."

The "Richmond Girls" face 180 felony counts, officials said.

Saturday, July 12, 2008

Credit card fraudsters target a Cotswold garage - thisisgloucestershire.co.uk - 09 Jul 2008

Dozens of customers of the Murco petrol station on the A40 at Andoversford were contacted by
their banks following suspicious withdrawals on their credit and debit card accounts – in countries such as Jamaica.

Police believe a skimming device that copies card information could have been fitted to the garage's credit card swipe machine.

Details were then used in cloned cards to withdraw money and buy goods.
Police searched the garage on Saturday as well as addresses in Cheltenham and Churchdown.
Filling station owner Ajitha Edirisinghe said his industry seemed to be “prone” to being targeted.

He said: “It's started everywhere in petrol stations but it's a shame it's happened to us.
“I feel so bad for all our customers because most are regulars.
“I've been here for six years and built up such a good relationship and never had such a problem before.

“Today we've been told to take over the system manually. We're ringing the card companies for authorisation for each transaction.

“We get 300 to 400 customers a day using their cards.
“It's going to cost me a lot because I've had to hire extra staff to cope.
“But we will ride this bad time and it's business as usual.”
The fraudulent transactions relate to cards used at the garage between May and the first week of June.

But investigating officers are keeping an open mind as to when customers had their data stolen and when the cards were actually cloned.

Murco UK and Mr Edirisinghe are co-operating fully with inquiries and the device has been seized for forensic examination.

North Cotswolds acting police Sergeant Tim Griffiths said: “We received the first report of possible credit card cloning relatively early last Thursday morning.

“It was soon apparent many in the area had fallen victim to numerous fraudulent transactions on their debit and credit cards.

“All high street banks have been informed of the issue and police inquiries are ongoing.”

Anyone who has used a credit card at the garage during the suspected time and noticed suspicious withdrawals from their account is advised to contact their bank immediately and then inform police on 0845 090 1234.

The rural garage hit the headlines in April 2007 when a robber showed part of a gun to a cashier and demanded the cash box containing £400.

Identity Thieves Skimming From Grand Valley Residents

Police are warning residents to keep tabs on their credit cards after thousands of numbers are stolen. Thieves have stolen nearly $150,000 from 40 people since February through skimming. According to Grand Junction police, there is an average of $2,000 dollars stolen during each of the incidents. Police say the suspects' employers and co-workers had no way of knowing the crime was taking place. Police won't release what local businesses are being investigated.
Ways to protect yourself are knowing where your cards are at all times and comparing receipts to your statements. Keep your PIN in a safe place away from the card and always report suspicious activity immediately

Watch the video at http://www.krextv.com/video_player/player.php?file=http://krex.tv/uploads/48056c22-77df-75ff.flv

Sunday, June 29, 2008

The inside story of ATM fraud - sunnewsonline.com - 28 Jun 2008

Until the unthinkable happened, Adah Obande had always prided himself as a streetwise Nigerian. So streetwise he had never been a victim of pickpocket, burglary, room-to- let fraud, 419 scam or some high profile swindle. Caution was second nature to him; after all he was a security personnel trained to be one step ahead of criminals and their modus operandi. Both in his professional and private life his reflexes had never failed him as he had never lost a possession to a thief. However, his ironclad confidence was put to the test shortly after his return to Lagos from the last Christmas holiday.

Prior to the Yuletide, Obande had left the sum of N288,000 in his bank account. The last withdrawals he remembered doing were for the sum of N50,000.

Specifically, he withdrew first the sum of N20,000 from the Obalende branch of his bank. Then on 22nd December, the very day he set off for the village, he made another withdrawal of N30,000, this time using the Automated Teller Machine (ATM) at the Falomo branch of the same bank.

If his arithmetic was correct, Obande still had a tidy sum to start the New Year on a bright note. Unknown to him, he was in for a shock treatment as he glided across the polish floor of the bank to the counter. The cashier punched her buttons and then gave Obande an awkward look. “Sir, are you expecting any lodgement?” she asked as pleasantly as she could.

Obande was not expecting any deposit. He still had N288,000 left with the bank. Or so he thought. His account was in the red. He urged the cashier to check again, insisting there was a mistake somewhere. It was only a matter of minutes before the full explanation was given to him. The man almost had a heart attack as he was told that the N288,000 had been withdrawn via the ATM.

Before this shocker in the banking hall, Obande indeed had tried to withdraw some money in the morning of January 7th, 2008, using the ATM. At first, he had thought there was a problem with his ATM card because no matter how hard he punched, the machine kept telling him his account was empty. When he realized he might be in for a long haul, Obande accepted the advice of the bank staff at the Falomo branch of the bank to proceed to the bank’s headquarter at Marina. There he was handed over to one Mr. Tony who in recent times has found his job a little bit more fatiguing. Like his counterparts in almost all the banks, his desk is flooded on a daily basis with ATM-related complaints.

Investigations into Obande account would reveal that two faceless companies swept his N288,000 using the ATM.

The companies, or rather their addresses were given as www.immigration.com and www.earocontractor.com. The victim swore the companies did not belong to him. He never worked for them and had no business relationship with them. The theft was later reported to the Special Fraud Unit of the Nigeria Police.

On Thursday, June 5, between the hours of 1.20-3.10 p.m, this reporter was in the premises of the Opebi branch of First Bank, observing ATM users and their seeming frustrations. Of the 26 customers that used the cash dispenser within this period, not a few came out cursing under their breath. The issues ranged from cards trapped inside the machine to PIN (Personal Identification Number) rejection.
One particular customer, a middle-aged man was left with little choice but to cause a scene as he protested that the machine had cheated him.

Before his very eyes, the ATM machine had processed his request but instead of dispensing the cash, the machine merely opened his mouth, brandished the crisp notes for the eager customer to see, and then swallowed the money all by itself. For his troubles, the bewildered customer received instead a receipt of transaction showing he had just successfully withdrawn N15,000. A security guard, who from his grin was obviously familiar with the various ATM antics, did his best to calm and reassure the agitated customer. He would lead him inside the bank’s building to lay complaint on yet another ATM ruse.
If the myriad incidences witnessed that day at Opebi could be glossed over as part of the teething problem of e-payment system introduced to the economy only a few years ago, the same cannot be said of the loss last week of N175,000 to ATM fraudsters.

The victim, this time, is a media practitioner. The man, Mr. Iheanachor, told SATURDAY SUN that on the particular day, he had first attempted to withdraw some money using the ATM in the premises of Guarantee Trust Bank in the Okota area of Lagos. When that proved unsuccessful, he proceeded to Zenith Bank at the same Okota. The outcome was grimly the same. A third attempt, this time at Eko Bank in the same neighbourhood fetched him N20,000 cash. For him, the end would have justified all the troubles but for a text message that came some hours later from his bankers, Intercontinental Bank, informing him that N175,000 had been withdrawn from his account via the ATM. From bank records, the N175,000 was withdrawn in eight transactions. The account holder said he knew nothing about those withdrawals. The matter is under investigation.
On the rise
Every week, hundreds of bank customers across the major cities are finding their deposits or a substantial part of it stolen by faceless crooks. Sources within the Special Fraud Unit (SFU) confirmed that ATM fraud is on the increase in Nigeria. The statistic is alarming. The Central Bank of Nigeria (CBN) puts the losses to ATM-related theft last year alone at hundreds of millions of naira. It is about the commonest headache to all the banks in Nigeria and one seen by experts as capable of eroding in the long run the enviable gains of recapitalisation. At the moment,

By EMMANUEL MAYAH

Sunday, June 22, 2008

Credit card blues: Cops unearth Rs 1-cr fraud - Indian Express - 21 Jun 2008

Over 30 customers of Le Meridien cheated

Unearthing a major credit card fraud, the Crime Branch of Pune police have arrested a gang of four persons for cheating people and creating duplicate credit cards. The gang is alleged to have cheated over 30 customers of Hotel Le Meridien to the tune of Rs 1 crore, according to the police.

The gang was headed by 24 year-old Asif Zaidi Mirza of Borivli, Mumbai, who though only a HSC pass, is technically quite savvy. Among the other accused, Wasim Salim Patel (21) of Sainik Nagar in Yerwada was a cashier at Chingari Restaurant in Hotel Le Meridien. The other two accomplices were identified as Ubed Ajmat Sayyad (26) of Mumbai East and Bharat Tansukhbhai Soni (28) of Goregaon, Mumbai.

Senior police inspector Sunil Pawar said the accused had been stealing the credit card details of the Le Meridien customers with the help of devices like “credit card skimmer” and “credit card reader” that they had purchased from a Nigerian national for Rs 60,000.

“When a customer gave credit card for paying the hotel bill, Patel used to swipe the card using the skimmer whereby the credit card details were recorded for later use,” said Pawar.

“The accused then copied these details on the magnetic strips of blank or blocked plastic cards using computer technology. In this manner, they prepared at least 33 credit cards of 27 multinational and international banks. These credit cards were circulated among the gang members, who used it for shopping costly items,” he said.
“The fraudsters were mostly targeting customers having platinum, gold and corporate credit cards who have credit limit of about Rs 15 lakh in India,” Pawar added.
The fraud came to light, when Sunil Nade (33), manager of Financial Resource Management (FRM) division of Citibank’s East Street branch lodged a complaint with the Bund Garden police station a few days back.

Nade and three of his bank customers had gone to Hotel Le Meridien on May 7 for dinner during which time the accused Soni, Asif and Ubed were also present.
The police suspected that when Nade gave the credit card for making the payment, the cashier Patel either stole the credit card details himself or passed these cards to his accomplices for the purpose. Then they used the duplicate card for shopping goods worth Rs 10 lakh.

Nade and the other three bank customers were shocked when they came to know that such a huge amount was withdrawn from their account without consent between May 7 and June 13. And they approached the police.

Acting on a tip-off, the crime branch sleuths first nabbed Soni at Mumbai. Later, they arrested Asif, Ubed and Patel. Police have seized the skimmer, credit card reader, laptop and 20 duplicate credit cards.

Investigations revealed that Patel was working at the hotel for last three years. Asif, the gang leader, was taking as his cut 50 per cent of the money made from the fraud. “It is very easy to identify a duplicate credit card. Still some shop owners have allowed shopping through such cards. We suspect that fraudsters paid some part of their income through the racket to the shop-owners,” said Pawar, whose was assisted in the investigation by sub inspectors N V Avhad and R M Gaikwad.
When contacted, Jaswinder Narang, General Manager of Le Meridien said that police had apprehended Patel about three days back. “Police have not communicated with us later. Also, we have not received any complaints from the customers,” he said.

Wednesday, June 11, 2008

Report: Thieves Target Online Travel Sites - csoonline.com - 09 Jun 2008

Online travel sites and airplane parts manufacturers are among the biggest victims of cybersquatting, false association, pay-per-click abuse and domain kiting, according to a new report from security vendor MarkMonitor.

The vendor points to the increased risk in those business sectors in its newly released Brandjacking Index for the spring. The findings reflect a trend observed by other security experts who have found, among other things, that the bad guys are using search-engine optimization (SEO) tricks to get their bogus sites higher in the search rankings.
Trends noted in the report included:

The rise of online auctions for fraudulent travel vouchers. The average discount for the more than 150 listings analyzed was 80 percent under face value. With the recent airline industry bankruptcies, increased cases of online fraud related to refunds, credits and vouchers are likely.
The growing success of search engine optimization tactics. Through higher search rankings, scammers divert Internet users searching for legitimate travel brands to illicit sites with questionable content, including pornography.

Blended abuses targeting travel brands. Attackers have combined multiple techniques such as spam, pay-per-click fraud and malware to put shoppers' computers as risk for viruses and spyware.

Meanwhile, the vendor found that cybersquatting is the most pervasive form of brandjacking, growing by 40 percent in the first quarter of 2008, while pay-per-click fraud actually declined by 42 percent. Phishers also appear to be targeting fewer new organizations, focusing 90 percent of the phishing activity on a small number of brands.

Dancho Danchev, an independent security researcher and consultant based in the Netherlands, said the MarkMonitor research reflects much of what he has been monitoring in recent months.
"What I've been witnessing is an automated approach that comes up with relevant brand impersonating domains such as anti-virus-2008.com, registering these and uploading the fake security software," Danchev said, adding that scams are getting more sophisticated due to the localization crooks are starting to apply even in the domain names themselves - registering the domains in a native language to attract local traffic, for example.

Where the money is During a recent visit to the offices of CSOonline to promote the latest Brandjacking Index, MarkMonitor Chief Marketing Officer Fred Felman said he's not surprised by the explosion of online travel scams designed to lure shoppers from legitimate e-commerce sites. But he was taken aback by the number of bogus sites selling questionable aircraft parts on business-to-business exchanges and consumer auction sites.

"The criminal is always thinking about where the money is, so it makes sense they would go after travel sites," he said. "We all travel and are frustrated by the high cost of airline tickets and hotel rooms, so we're constantly looking for bargains."

He's also not surprised the bad guys are making so much money since, as Danchev noted, they are getting more adept at using cybersquatting and SEO tactics, a trend reflected in a recent special report from CSO magazine (Black Hat SEOs: Is This the Future of Search?).

Danger in the skies? Though he wasn't surprised to see travel sites targeted so aggressively, Felman said he was shocked by research showing vendors in China, the U.S. and other countries selling questionable aircraft components in bulk online.

"Given all the regulations out there, it's surprising that we found so many bogus parts sites," he said. "There's a growing risk that these parts could end up in standard distribution channels."
Other security experts are far less surprised to see bogus airplane parts proliferating across cyberspace. For them, the China connection in particular is a no-brainer.

"I'm not surprised by anything coming from China," said Petko D. Petkov, a self-described hacker and founder of UK-based think tank GNUCITIZEN. "The cyber laws in China are a bit vague and [hackers] are usually left to do whatever they want without consequences."

Independent security consultant and former Radianz CSO Lloyd Hession noted that there has always been a market for bogus plane parts and that people have been traveling for years in planes fitted with some of the questionable components. It's just that the bad guys have finally taken their business online, he said.

Security options limited While companies can reduce the threat to their reputations through a layered security program and constant surveillance to see if their brands are being abused, Petkov said defensive options are limited.

"In the case of brandjacking, I don't think there's an easy solution due to the fact that the people who abuse the particular brand may not reside within a country that has sensible regulations" to deal with the practice, he said.

In cases where phising attacks happen via a third-party domain the targeted company has no control of, there is very little to do, he said. One can contact the ISP in charge of the domain or the hosting space with the hope that they will terminate it, or report the malicious URLs to numerous anti-phishing registers.

Unfortunately, he said, "none of these workarounds will be 100 percent effective."
For its report, MarkMonitor analyzed feeds from leading international ISPs, e-mail providers and other alliance partners.

By Bill Brenner

Sunday, June 8, 2008

"I'm in Singapore" claim phantom fraudsters - channel news asia - 06 Jun 2008

SINGAPORE: Duped by fraudsters in a credit card scam, American businessman Steve Mozena was astonished to discover the transaction apparently originated from a country reputedly tough on crime — Singapore.

"As a result, I have been cheated out of nearly US$9,000 (S$12,300), which is a large amount for a small business like mine," wrote Mr Mozena, who owns a small medical equipment and supplies store in California, in an email last week to Today.

He is not alone: Since 2002, various reports have surfaced of credit card-related scams committed by companies or individuals purporting to be in Singapore. The Commercial Affairs Department has received more than 70 complaints from online merchants overseas since 2003.

However, on Thursday, a Monetary Authority of Singapore representative denied that such cases are on the rise.

The spokesperson pointed out: "The cards used in such schemes may have been issued from anywhere in the world, and any number of countries could be used as transit, forwarding or distribution for goods purchased through card-not-present fraud schemes."

The police believe the fraudsters are not based in Singapore.

Since January last year, the US Embassy has carried an advisory on its website urging online sellers to check the legitimacy of the cards if they get an order supposedly from Singapore.

But wherever the real origins of the fraudsters, their actions present a nightmare for small time businessmen like Mr Mozena, as credit card companies inform them of the swindle only after the goods are shipped, in some cases weeks later.

While the legitimate cardholders are not liable for the charges, the business is responsible for a "charge back" — a reversal of a credit card transaction to the merchant.

To make matters worse, they also no longer have control over the items sold. Said Mr Mozena: "I have contacted my insurance broker to see if my business insurance covers the loss. Though if it does, it’s likely my insurance premiums will go up."

The US Embassy advisory cautions traders that orders — placed via telephone or online and usually in the region of US$5,000 to US$30,000 — sent to Singapore could be redistributed elsewhere and, if this happens, the cost of recovering the goods is "prohibitive".

When contacted, the embassy was not able to give any indication of the number of cases reported, as "any crimes that take place in Singapore are under the exclusive purview of the Singaporean authorities".

A police spokesperson told TODAY that between 2002 and 2003, the fraudsters' modus operandi was to simply add "Singapore" as part of the shipment consignee’s address, even though they were located elsewhere.

But from 2004 on, these cheats began using the contact details of bona fide freight forwarding companies in Singapore as the consignee. Once the shipments arrived in Singapore, the cargo would be redirected elsewhere.

As such, the CAD has been working closely with US law enforcement agencies and regional police forces, other government agencies and industry players through fraud information sharing. They have also helped victims recover goods worth more than US$350,000, said the police spokesperson.

Despite these efforts, traders like Mr Mozena continue to fall prey to such cons. The police say, public education is the best way to convey the message: Online traders can protect themselves by exercising “greater caution when processing orders from questionable customers who place exceptionally large or unusual orders, provide questionable contact details or multiple credit card numbers for payment”.

Mr Mozena admits that he was not as careful as he could have been. "My company has been in operation for less than a year and my website was not yet secure," he explained.

"These credit card criminals obviously prey on websites not yet finished or secure. But does this make it my fault for being too trusting, especially in dealing with people apparently from a country that is known to crack down hard on crime?"

Meanwhile, the MAS is collaborating with the banking industry to keep an eye on the issue.

"Banks are required to have in place robust fraud detection and prevention controls, as well as remedial procedures to minimise the incidence of credit card fraud," said their spokesperson. - TODAY/sh

For fraudsters, ATM is indeed all time money! - The Economic Times - 07 Jun 2008

MUMBAI: Internet banking and credit cards are not the only targets on a fraudster’s radar. ATMs are also fast emerging as soft targets with fraudsters constantly evolving their techniques.

Recently, an ATM of a public sector bank in Nagpur was hacked by a member of the maintenance staff. In a comparatively crude attack, the maintenance employee tapped the wires connecting the machine to the server using a small transistor-like device. The device basically intercepts the signal and stores it, making it possible to replicate it later.

So, when an unsuspecting customer walked in to the ATM centre, the digital signals passing from the machine to the bank’s server were tapped. These signals were then re-sent from the back of the ATM machine with the fraudster’s accomplice standing in front of the ATM slot for withdrawing money without actually carrying the ATM card with him. Since the server received the same signal from the ATM as that of the cardholder wanting to withdraw cash, it dispensed the same amount once more.

Thursday, June 5, 2008

Beware ATM crooks - edmontonsun.com - 03 Jun 2008


Edmonton police are asking for the public's help in identifying the male suspect who is seen in this picture installing a pinhole camera in the valance above an ATM as part of a card-skimming operation in the city. (Supplied photo)
New dogs are up to old tricks, costing Edmontonians an untold amount of cash, warn cops.
Police announced yesterday they have discovered more bank card skimming operations in the city.

Now they've issued a public plea to help identify a man suspected of installing illegal equipment.
That suspect, believed to be part of a team of crooks targeting bank ATMs, was captured in a photo that appears to document him installing a camera above a cash machine.
Scams have been uncovered at several Edmonton financial institutions, although police declined to identify which ones.

Customers became victims of the crime after swiping cards to gain access to banks, cops said. Detectives believe magnetic stripe information is gleaned during that step.
Criminals also installed cameras above bank machines, allowing them to view users inputting personal identification numbers, say police.

There's nothing innovative about it, said Det. Al Davis, of the Edmonton Police Service's economic crimes division.

"It's actually an old trick redone again," Davis told Sun Media. "These guys develop a technique and stick with it."

Though police believe this particular crew began their crime spree in Calgary, Davis said almost all of the 15 documented offences occurred in Edmonton.

That concerns some city shoppers.

"I want to be very careful," said retiree Peter Dyck, who just returned from a seven-week trip to British Columbia.

"On our trip to Vancouver, Kelowna and Victoria, I seldom used my credit card. I got cash out of the bank and used it instead."

When Dyck does use money machines, he said he's always looking over his shoulder to ensure he isn't being spied on.

Such precautions would likely be lauded by Davis, who advised consumers to take numerous steps to avoid becoming victims.

"Covering your PIN will prevent the bank account from being accessed," Davis said. "It will prevent the crime."

He noted consumers should also give ATMs the once-over before inserting cards, to ensure unusual pieces of equipment aren't attached.

"If you see something that looks odd, grab ahold of it and see what happens," he said, adding pieces installed by crooks often detach easily.

Police aren't certain how much cash the crooks have made off with, but Davis said it's likely significant.
By MICHELLE THOMPSON

Cayman Islands Police Warning Issued on Jewelry Scam - israelidiamond.co.il - 04 Jun 2008

Police have issued a warning to jewelry store owners and managers to be on the lookout for a scam currently targeting the Cayman Islands.

According to the Royal Cayman Islands Police Service (RCIPS), a number of local stores have been contacted by people ostensibly interested in purchasing expensive watches in the $25,000 price range. The scammers asked to spread the purchase over five or six credit cards, some of which go through, while others are declined.

In an attempt to prove that the credit cards are genuine, the scammers sometimes fax passport photos, signatures and copies of the credit cards bearing their name to the jewelry store.

According to the Financial Crime Unit (FCU), fake cards have been made based on the numbers of stolen cards, and fake cards have been produced bearing the stolen card’s details.

Detective Constable Sherry Francella said local store managers have been extremely cooperative so far and have even sent empty boxes to the perpetrators in an attempt to apprehend them.

Francella noted: “It appears this scam is originating from London and it is hoped that by sending the empty boxes police in the UK will be able to identify the offenders.”

By: Rachel Lieberman,

Wednesday, May 28, 2008

CARD CLONING SCAM PROBE - bournemouthecho.co.uk

MOTORISTS are being urged to check their bank or credit card statements after police investigating a card cloning scam raided a Bournemouth filling station.

Officers swooped on the Texaco Malthurst West View Service Station in Charminster Road just after 9 am yesterday.

They shut the garage to members of the public while they searched the garage for evidence. The premises remained closed and deserted yesterday afternoon.
Dorset Police say they have so far received more than 25 calls from worried members of the public alleging bank card fraud.

Among those affected was United Taxis driver Simon Mowels. "My business partner phoned me on Sunday to say he'd had a call from Abbey National's security centre," he said.

"When I checked online I found there had been three transactions, but they weren't huge.
"The bank has been very good. As far as we're concerned, it's only about £100 and we'll get it back."

Another person affected was Daily Echo feature writer Gavin Haines, who was alerted by his bank after money was withdrawn from his account in Madras, India, on Saturday, Sunday and Monday.

"I can't afford to lose £400 on a weekend. It was my only bank account at the time and they didn't have access to money. I've now got to go through the claims process," he said.

Last year, police received more than 200 similar complaints about the Murco service station in Southbourne Grove, Bournemouth. Three men were arrested but were later released without charge. The garage is under new management.

Card-cloning, sometimes known as skimming, involves retrieving card details and pins (personal identification numbers) to withdraw money fraudulently from people's bank accounts.

In spring last year, thousands of motorists were hit in a skimming scam involving garages across England. The Sri Lankan government claimed the money was being used to fund Tamil terrorist activity on the island.

The latest allegations in Bournemouth are being investigated by officers of the cheque and card unit of Dorset Police's economic crime unit.

They are warning members of the public to make sure they are not being watched when putting in their pin. People are advised to move mobile pin machines if they feel they are being watched, and to always hide the key pad with their hand when entering the number.

Anyone who feels their card has been compromised is urged to report it immediately to their bank and to the police on 01202 222 222.

Two Bournemouth men, one in his 20s and another in his 40s, are helping police with their inquiries after being arrested on suspicion of conspiring to defraud the banking industry.

By Joanna Codd

Tuesday, May 27, 2008

ATMs play bigger role in identity theft - bankrate.com

Before Jay Foley inserts his bankcard into an ATM slot, he sticks his finger in first. Then, he wiggles it.

"If any portion of it wiggles with my pinky, I walk away because odds are somebody has slapped a skimmer on the front," says Foley, executive director of the San Diego-based Identity Theft Resource Center. "That applies to any kind of payment slot you might run across, such as gas station pumps. Those are favorite places for thieves to work now."

A skimmer is a device that reads and records all the account information stored electronically on the magnetic stripe of an ATM card. Its mere existence is proof that if you thought familiar, ubiquitous automated teller machines were much too low-tech to attract high-tech cyber-thieves, you need to think again.

Fraudsters have returned to ATMs in force as a favorite fishing hole for that prize catch: your debit card. With a little light mechanical tampering, thieves can "harvest" your account details and PIN number in seconds, then use them to either produce a "clone" card or to simply shop online until your account runs dry.

"The number of victims we get from debit fraud or ATM fraud is growing every year, and it's growing significantly," Foley says. Increased dangerATM crime is increasing now that stepped-up fraud detection software on the credit card side has made signature cards more difficult to attack. Increasingly, thieves are preying on more vulnerable, PIN-based debit cards.
Doug Johnson, vice president and senior adviser of risk management policy for the American Bankers Association, acknowledges that ATM skimming may be getting worse.

ID Theft By Numbers

Amount of Time - 12 Months

Number of Victims - 3 Million

Total Loss - $2.75 Billion

Average Loss - $900

For complete post refer to the link http://www.bankrate.com/brm/news/Financial_Literacy/identity_theft/ATM_fraud_a1.asp?caret=93h

By Jay MacDonald

Monday, May 26, 2008

You swipe, they strike: the great card fraud - TOI Chennai - 26 May 2008

As More And More People Switch Over To Plastic Money, Tech-Savvy Conmen Are Finding Newer Ways To Rob Unsuspecting Credit Card Users

Chennai: The busting of a city-based gang that forged identities to acquire 70 credit cards and liberally draw cash to the tune of Rs 65 lakh from banks highlights the great risk that credit card users are exposed to.

The risk is threepronged, according to the bank fraud wing of the city police. One, when you lose your credit card, it may be misused by some crook. He or she can then use the card to withdraw cash and buy valuables.

Two, when you throw away an expired credit card, the crook could take the credit card and decode the secret numbers on the magnetic strip. Along with the name and the card number, he or she can prepare a forged credit card and encash it.

Three, is when credit cards are cloned. Sometimes, employees at shops swipe the card in a separate machine to decode the details of the magnetic strip in the original credit card, before swiping on the actual machine. In some places, the secret personal identification number is noted discreetly by hidden cameras.

The cloning involves a process called skimming in which information on the card is recorded on a device known as a skimmer. Skimming is turning out to be a huge menace across the world. “You are at maximum risk when you hand your credit card to a waiter or cashier to pay your bill in any shopping mall or restaurants. The skimmer could be tucked away in someone’s pocket and your secrets could be read in a flash.”

Police begin investigation into such white collar offences in a syatematic manner. Thanks to the availability of the voluminous data, they can now easily work out how a crime is committed. Sometimes, investigating agencies manage to nab criminals using close circuit televisions fixed in shopping malls and ATMs.

“Most of the cases are exposed through bank officials. Based on the information given by them, the police narrow down on culprits,” a police officer said. Balakrishnan, who works as a direct agent for a private bank in Chennai, said, “We approach people based on their profile to provide them a credit card. Sometimes to achieve the target, we are helpless and send some of the documents to the bank even though we knew that the documents are fake. We do this just for the sake of the commission.”

The private banks have snapped the dealership of many agents, after we exposed the their connivance with the fraudulent customers, a senior police officer said. The city police’s bank fraud wing has received at least 180 complaints from various banks against the fraudsters in 2006 and 2007.

In the case of credit card fraud, the bank fraud wing has received more than 60 complaints in the past three years and in most of these cases, the police have arrested the culprits, police sources said. CAUTION IS THE KEY Credit and debit card fraud is a multi-million dollar industry worldwide.

Fraudsters in UK alone netted £504.8m in 2006. Here’s how you can keep your cards safe Be alert whenever someone wants to take your card out of your sight, as in petrol pumps Never let your card out of sight and check receipts and bank statements thoroughly. A card swiped in India can be duplicated in the US and perhaps used there Your credit card receipt is often enough to reproduce a replica. Customers in the US are advised to shred all their card receipts

You are most at risk when the fraudster can easily guess your card PIN number so avoid using easily traceable facts about you as your PIN number. If you have multiple cards, have a different PIN for each one SKIMMER A ‘skimmer’ is a battery operated magnetic device, hardly three inches long, which can copy the details of the magnetic strip on your credit/debit card, PAN card or driving license to reproduce a cloned card Most skimming has been known to occur at retail outlets: bars, restaurants, shopping complexes and petrol stations. Sometimes the store employees (waiters, cashiers) are involved in the racket

The skimmer may either use your data on his own or sell it off to a bigger racket, which may even use it in another country. A single skimmer can copy the data of 32,000 cards GONE IN A

FLASH: YOU GO SHOPPING... AND GET A SHOCKER

A Selvaraj TNN

Saturday, May 24, 2008

Credit card fraud just got bigger and worse! - Rupee Times - 23 May 2008

Keeping a credit card just got a bit more expensive! Stealing and using a credit card are passé. In today’s world, hackers are working overtime to find out new innovative ways to make new money, and going by the look of things, they are gaining a sizeable lead in this domain! From skimming and cloning your credit card, to making fake sites; from using stolen cards on them to using new online trading models, the cyber thieves are on prowl to hack into your bank account.
Now, it’s no longer safe to trust a restaurant employee or petrol pump attendant with your credit or debit card. Many cases of multiple cards being ‘skimmed’ and ‘cloned’ are being reported to the police and bank authorities, and many of them are originating when a customer is least expecting it! So next time, think twice about giving your credit card in a restaurant or in a petrol pump! Card thieves are using magnetic stripe readers and encoders which are easily available in the market for $250-$600.

While a card reader can read the data on the magnetic band of your credit or debit card, an encoder can encode it on to any plastic card with a magnetic band, even a normal hotel room key.

Rajat Khare, who is the founder director of network security management company, Appin, said, "All credit cards can be cloned by simply inscribing cards with a similar magnetic band just like a hotel number is fed into a magnetic room key. These kinds of card frauds are becoming common."

Banks are trying to fight this menace, by advising customers to subscribe to mobile alerts. ICICI Bank card products head Sachin Khandelwal said, “We have a 45% market share with about 8.5 million credit cards in the market. The percentage of card frauds is low at about 4 basis points of all transactions. Nevertheless, we shoot an SMS alert for every transaction above Rs 2,000 to all our customers. Skimming of credit cards is generally done when a customer places a mail or phone order transaction.”

However, certain banks, like HDFC, do not stop at mobile alerts. In additions to the alerts, the bank also provides an extra security layer for all credit and debit card customers. Through this facility, the cardholder can create his own additional password, which provides an additional security layer for all On-line transactions, said HDFC Bank credit card marketing head Parag Rao.

If you have just received a new credit card from the bank, but discover that it already has a charge attached on it, don’t be surprised. These days credit fraud happens even before a new card has been received from the bank. Credit card number generators are freely available online (on sites like http://www.brothersoft.com) which claim to generate card numbers of various companies starting from ‘5’ (Master Card) or ‘4’ (Visa) or other digits. It also generates 13, 16, 18 or 19 digit card numbers. These generators use the same algorithms like `Luhn formula’ used by government agencies and banks to generate numbers.

“In one case, a hacker managed to crack the algorithm of a bank’s credit card generator and sold hundreds of numbers online. So even before the fresh card came into customer’s hands, they already had a charge on them. In another case, a credit card hacker set up a site and started using stolen card numbers to provide downloadable images and managed to siphon off about $2 million,” adds Mr Khare.

However, the biggest wrath of the credit card fraud can be felt in the E-commerce portals, which have also become like trading havens for hackers. This is how it works: A hacker enters the stolen card number and CVV (card verification value) number, as mentioned on the reverse of the card, into an e-commerce site and buys a product. The payment is made but the buyer doesn’t take the delivery immediately. He gives the delivery date – of generally a week to 10 days. During this time, the hacker posts his costly buys (from the stolen card) on the portal for sale obviously for an even lower price. As the hacker gets a customer for his product, offered at a jaw dropping price, he gives the customer’s address as the delivery address, on the same or other portal.

He receives cash from the final customer in an electronic cash account or an escrow account from where he converts it into hard cash. Escrow is a legal arrangement in which an asset (such as cash, real property or other tangible assets) is deposited into safekeeping (e.g. a bank account) under the trust of a neutral third party (escrow agent) pending satisfaction of contractual contingency or condition. Once the condition has been met, the escrow agent will deliver the asset to the party prescribed by the contract.

Thus during the entire transaction the hacker can manage to cruise through without leaving a trace. Says IT risk and consulting firm Mahindra Special Services Group Captain, Raghu Raman, “Most hackers try and steal small amounts–just 2-3% of a monthly transaction to avoid getting caught. In large transactions, the banks usually call and ask the customer immediately to cross check whether a transaction was done by him. Hackers are also using card numbers to get a subscription or download a costly software which they in turn sell it online.” Thus, this makes it difficult to catch them also.

However, all is not lost for the credit card customers. There are certain precautions which one can adopt so as to be on the safe side. Net security experts have warned that web transactions with credit cards are no longer 100% safe. They suggest the use of credit cards only on sites which are ‘Https’ (Hypertext Transfer Protocol over Secure Socket Layer) and direct the transaction webpage to a payment gateway. Deleting cookies and browsing history from your computer after a transaction might also help prevent the cyber thief stealing your card number.

By Ankit Sharma

Friday, May 23, 2008

Shoppers hit in bank card cloning scam - bdpost.co.uk - 22 May 2008


FRAUDSTERS cloned dozens of shoppers' bank cards - then posted the counterfeits abroad to withdraw money.
The scam known as 'fraud abroad' has affected dozens of residents in Barking and Dagenham, including council workers.Morrison's supermarket in Wood Lane, Dagenham, is believed to be the source of the crime which has seen thousands of pounds stolen from bank accounts.
Tony Knight, 41, a postman from Dagenham, said: "They stole two thirds of my wages using cash machines in South Africa."I had direct debits coming out and bills to pay - I didn't know what I was going to do."I couldn't fill my car up with petrol, or go shopping."And I'm still scared to use my card now, I don't know where's safe."The thing is that my wife and I never shop in Morrison's, we hadn't been there for years until a month ago - we always go to Asda or Tesco."
Security controller for Morrison's, Simon Lambert, said: "We can confirm that we have been made aware of an incident at the Beacontree Heath store. "Customers who think they may have been affected by the problem should contact their bank immediately, and speak to the fraud department."
Pakistan, India, Argentina, Egypt, and the USA are just some of the countries where this network of fraudsters appears to be operating.It is unclear how long the massive operation has been going on, and banks including Barclays, and the Royal Bank of Scotland were among those affected.APACS is the UK trade association which works with banks and police to ensure that fraud is prevented.
They are working with the Metropolitan police service in the investigation of this case.A police spokesman said: "We are investigating a number of cases of credit card fraud thought to be linked to a store in Beacontree Heath.
"APACS say card fraud losses for banks have increased 25 percent as fraud abroad is up £90.5million, and accounts for more than a third of all card fraud losses. Criminals steal details from magnetic stripes on the backs of cards to make counterfeits and use pinhole cameras to record people's PIN.
They then withdraw the money in foreign countries which have yet to upgrade to chip and PIN.Sandra Quinn, director of communications at APACS, says: "Although card fraud levels have begun to go up again due to fraud abroad, chip and PIN has proven to be an undoubted success in reducing card fraud on the UK high streets."And, as more countries follow our lead and upgrade to chip and PIN, the opportunities for criminals to use our stolen magnetic stripe details overseas will decrease.

Paying petrol bill with your card? Watch out - Economic Times - 22 May 2008

NEW DELHI: Hackers around the world are getting innovative. From skimimng and cloning your credit card, to making fake sites; from using stolen cards on them to using new online trading models, the cyber thieves are working overtime to hack into your bank account.
If you think that giving your credit or debit card to a petrol pump attendant or a restaurant waiter is safe, think again. Chances are that it would be ‘skimmed’ and ‘cloned’ into multiple cards by the time you reach home, warn security experts. Card thieves are using magnetic stripe readers and encoders which are easily available in the market for $250-$600. While a card reader can read the data on the magnetic band of your credit or debit card, an encoder can encode it on to any plastic card with a magnetic band, even a normal hotel room key.

Says network security management company Appin’s founder director, Rajat Khare, “All credit cards can be cloned by simply inscribing cards with a similar magnetic band just like a hotel number is fed into a magnetic room key. These kind of card frauds are becoming common.” Banks are advising customers to subscribe to mobile alerts. ICICI Bank card products head Sachin Khandelwal said, “We have a 45% market share with about 8.5 million credit cards in the market. The percentage of card frauds is low at about 4 basis points of all transactions. Nevertheless, we shoot an SMS alert for every transaction above Rs 2,000 to all our customers. Skimming of credit cards is generally done when a customer places a mail or phone order transaction.”

In additions to mobile alerts, HDFC bank also provides an extra security layer for all credit and debit card customers. Through this facility, the cardholder can create his own additional password, which provides an additional security layer for all On-line transactions, said HDFC Bank credit card marketing head Parag Rao.

Another kind of credit fraud happens even before a new card has been received from the bank. If you have just received a new credit card from the bank, but discover that it already has a charge attached on it, don’t be surprised. Credit card number generators are freely available online (on sites like http://www.brothersoft.com) which claim to generate card numbers of various companies starting from ‘5’ (Master Card) or ‘4’ (Visa) or other digits. It also generates 13, 16, 18 or 19 digit card numbers. These generators use the same algorithms like `Luhn formula’ used by government agencies and banks to generate numbers.

“In one case, a hacker managed to crack the algorithm of a bank’s credit card generator and sold hundreds of numbers online. So even before the fresh card came into customer’s hands, they already had a charge on them. In another case, a credit card hacker set up a site and started using stolen card numbers to provide downloadable images and managed to siphon off about $2 million,” Mr Khare adds.

E-commerce portals have also become safe trading havens for hackers. It works like this: A hacker enters the stolen card number and CVV (card verification value) number, as mentioned on the reverse of the card, into an e-commerce site and buys a product. The payment is made but the buyer doesn’t take the delivery immediately. He gives the delivery date – of generally a week to 10 days. During this time, the hacker posts his costly buys (from the stolen card) on the portal for sale obviously for an even lower price. As the hacker gets a customer for his product, offered at a jaw dropping price, he gives the customer’s address as the delivery address, on the same or other portal.

He receives cash from the final customer in an electronic cash account or an escrow account from where he converts it into hard cash.

Thus during the entire transaction the hacker can manage to cruise through without leaving a trace. Says IT risk and consulting firm Mahindra Special Services Group Captain Raghu Raman, “Most hackers try and steal small amounts–just 2-3% of a monthly transaction to avoid getting caught. In large transactions, the banks usually call and ask the customer immediately to cross check whether a transaction was done by him. Hackers are also using card numbers to get a subscription or download a costly software which they in turn sell it online.”

Transacting on the web with your credit card may not be 100% safe, say net security experts. They suggest to use your credit cards only sites which are Https (Hypertext Transfer Protocol over Secure Socket Layer) and direct the transaction webpage to a payment gateway. Deleting cookies and browsing history from your computer after a transaction might also help prevent the cyber thief stealing your card number.

Harsimran Singh, TNN

Card fraud at Shell garage runs into thousands - kenilworthweeklynews.co.uk - 23 May 2008

The number of people possibly affected by card fraud at a Hatton garage is still not known - but the amount stolen runs to thousands of pounds.

Readers from around the Warwick area contacted the Courier after criminals used 'skimming' devices to clone customers bank or credit card details to withdraw money in Australia and Canada.

Many were regular users of the Shell garage in Birmingham Road. Police have confirmed they are investigating fraud at a garage in the Hatton area.

Almost all said they had doubts about using cards to pay for petrol - and many say they will not be using the garage again.

of those affected was Hampton-on-the-Hill resident Tony Archer. Thieves used details 'skimmed' from his credit card to withdraw £593 in Australia.They began by taking small amounts but over two days the withdrawals rose from $50 Aus to $600 Aus.

He said: "It was quite a shock when I got the statement."I've never been to Australia and have no intention of going there."Mr Archer has cut up his old card and said he would no longer use credit cards to buy petrol, and would certainly not be using the Shell garage in Hatton.

Hatton resident Toni Lucas found £600 had been taken out in both Australia and Canada. She said: "I was shocked at first because I wasn't aware I would get the money back."It is amazing the number of people who have lost money just by going to buy petrol. It makes you not want to use your card."Mother of five Sharon Sloan, 36, of Hatton, had 500 Australian dollars - around £245 - stolen from the account she shares with husband Adrian. The family had to rely on relatives until her money was refunded and they received a new bank card.Mrs Sloan said: "You feel scared to use your card. You want to go back to using cash."Bubbenhall resident Maxine Jones only found out her details had been stolen when her card was declined in a shop. Around £178 had been taken out, also in Australia.The 47-year-old property developer said: "It is worrying that something like that had happened and it makes you concerned about how you use your card in future."It is the fact that somebody has your details."Shell had not responded to the Courier's request for a comment at the time of going to press.

Monday, May 19, 2008

Skimming Scam That Targets ATM Cards - KNTV.com

Technology is on the cutting edge now more than ever.
Most people use it to better their lives, but some use technology to take advantage of others.
Action News reporter Steve Ryan has more on a growing, hi-tech financial scam in the Valley.
For most people cash has taken a back seat to the convenience of credit and debit cards.
"I am afraid to use an ATM machine now, I really am," said Greg Pollak.
Greg Pollak was recently the victim of a skimmer, a small device that is a big problem.
"Somebody had their hand in my wallet, you know what I mean. I do not like that. I wanted to reach up and smack them across the teeth," explained Greg.
Greg lost hundreds of dollars to a skimmer, a magnetic stripe reader thieves use to record financial card information.
Lieutenant Robert Sebby oversees Metro's Financial Crimes Division and says thousands of people in the Valley have been taken for thousands of dollars.
Now police are out to take out the criminals, starting with the runners who do the dirty work.
"We routinely catch runners on the strip just about every weekend and a lot of those are willing to roll over on who the bigger fish are," said Lieutenant Robert Sebby.
Some skimmers are only about the size of a lighter, so criminals can put them in a lot of places quickly where financial information is used.
They tend to favor restaurants and gas pumps.
With technology now, they do not even have to come back to get the information off of the skimmer.
"They can be sitting across the way with a laptop with a wireless card. They can download your information and make a credit card right then and there while you are pumping your gas," said Lieutenant Sebby.
The safest way to protect yourself from skimmers is to always use a credit card, not your debit card, because thieves also have access to your pin number.
Credit cards offer your federal protection which is peace of mind that Greg wishes he had now.
"I felt totally confused. I mean, I was so disoriented that I did not know what was going on," said Greg.
He does not know when or if he will ever get his money back.
The criminals who took it could face several felony charges, including identity theft and burglary.
Skimming devices actually have legitimate uses too as they are used at conventions, to read room keys and gate access codes.
Stay tuned to Action News as we monitor developing news around the Valley