THE CENZIC BLOG
Read more articles in  Web Application Security Insights
.
March 25, 2009

Hacker Attack on Banks: PIN Cash Out Conspiracy

The PIN Cash Out Conspiracy is the latest hacker attack on banks

Financial institutions beware – there’s new scam hackers are using against your Websites and databases called the "PIN Cash Out Conspiracy".  And it’s costing you millions of dollars. 

It works like this:

  1. A hacker uses SQL Injection techniques to break into a database-driven Website which resides on a financial institution's network
  2. Then, they use their access to the bank's systems to locate the ATM database
  3. If necessary, the hacker alters the PIN for credit / debit cards they are planning on cashing out
  4. Then the hacker sells the card data to other criminals
  5. Those criminals create ATM cards using the hacker's information, and drain the accounts
  6. The hacker receives a percentage of the proceeds – around 10-20%

Call me greedy, but if I was the hacker, I’d ask for a larger cut.

During January and February 2008, the US Secret Service revealed they were investigating two such breaches involving this scam and the suspected hacker, Tenenbaum.  He was believed to have used this scam against OmniAmerican Credit Union (Fort Worth, Texas), and Global Cash Card (Irvine, California). 

In April and May of 2008, it is also known that there were breaches of this nature against Symmetrex, a transaction processor in Florida, and First Source Bank in Indiana.  Symmetrex cards were used by MetaBank - with branches in Iowa and South Dakota.  Actual losses of more than $4 Million were experienced just by those brands.

by
Douglas Simpson, Security Engineer
DSimpson@cenzic.com

Comments
.

RE: Hacker Attack on Banks: PIN Cash Out Conspiracy

Solution/System that can stop this
There is a system, there are systems that can stop this. I have been in this industry for quite sometime. It's not that hackers are smarter. The real problem is that Issuing Banks just are not implementing the right systems to protect their cardholders. I'm not talking about chip and pin only. There are other systems other than chip and pin that can eradicate this kind of fraud. 

It is really a sad commentary when it's easier to be a fraudster than to be a solution provider.
.
.

RE: Hacker Attack on Banks: PIN Cash Out Conspiracy

Frustration over why banks aren't taking security seriously

Hi Anne,

Yes, there are systems that are out there that can stop this.  I bet these organizations also knew about these systems too.  Does that not make you stop in your tracks and scratch your head and wonder, “why then were these “systems” not in place? 

In the end a breach is a good cure for insecure systems.  That is a sad state of affairs.

-Doug

.

Syndication OptionsRSS (Rich Site Summary) Feed Atom Feed OPML (Outline Processor Language) Feed MYST-ML (MyST Markup Language) Content Feed MS-Office Smart Tag Subscription