Feeds

Citibank ATM fraud 'just tip of iceberg' - analyst

PIN block card scam fears grow

Protecting against web application threats using SSL

An ongoing ATM fraud problem that forced Citibank into reissuing an unspecified number of US credit and debit cards is only part of a larger ongoing threat, a leading analyst warns. Avivah Litan, a research director at Gartner, said that Citibank is only one of a number of victims and that the banking industry is "less than halfway through this latest scam, which will continue to affect large numbers of cardholders".

Citibank said it blocked PIN-based transactions of Citi-branded MasterCard cards in the UK, Russia and Canada to protect US customer accounts. It blamed the problem on a security breach involving an unspecified US retailer. Litan, by contrast, suggests the theft of PIN data is the more likely cause of the security flap. She adds that other US banks have been forced to reissue ATM cards after customers' details were compromised.

"Gartner believes that these combined bank actions reflect the largest PIN theft to date — and point to a new wave of 'PIN block' card fraud," Litan writes. If hackers broke into retailer servers and steal PIN blocks that represent encrypted PIN data as well as terminal encryption keys (typically stored on retailers' terminal controllers), they might be able to determine a cardholder's PIN and create counterfeit cards that enable them to withdraw cash at ATM machines.

Litan reckons that this - rather than a simple retailer breach - accounts for a recent rise in ATM fraud affecting US banks. "In this particular scam, the thieves probably also stole (likely from a retailer) magnetic-stripe data found on the back of ATM cards, which large banks typically validate," she adds.

The Payment Card Industry (PCI) Data Security standard prohibits the storage of PIN blocks and covers terminal operations. Gartner advises card issuers to follow this guidance. The analyst firm also has advice for enterprises, payment vendors and regulators which can be reviewed here. ®

Reducing the cost and complexity of web vulnerability management

More from The Register

next story
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
Infosec geniuses hack a Canon PRINTER and install DOOM
Internet of Stuff securo-cockups strike yet again
Apple Pay is a tidy payday for Apple with 0.15% cut, sources say
Cupertino slurps 15 cents from every $100 purchase
Israeli spies rebel over mass-snooping on innocent Palestinians
'Disciplinary treatment will be sharp and clear' vow spy-chiefs
YouTube, Amazon and Yahoo! caught in malvertising mess
Cisco says 'Kyle and Stan' attack is spreading through compromised ad networks
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
Microsoft to patch ASP.NET mess even if you don't
We know what's good for you, because we made the mess says Redmond
NORKS ban Wi-Fi and satellite internet at embassies
Crackdown on tardy diplomatic sysadmins providing accidental unfiltered internet access
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Security and trust: The backbone of doing business over the internet
Explores the current state of website security and the contributions Symantec is making to help organizations protect critical data and build trust with customers.