Feeds

Fake ATM scam rumbled by Defcon hackers

Black hats in Fear & Loathing conference moment

Using blade systems to cut costs and sharpen efficiencies

White hat hackers attending the DefCon conference in Vegas last week uncovered the presence of a fake ATM in the show's venue.

Fraudsters placed a fake ATM kiosk in the Riviera Hotel Casino at an unknown time prior to the conference. The scam was uncovered after eagle-eyed hackers noticed something wrong with the machine.

"They looked at the screen where there would normally be a camera," Priest, a senior conference organiser, told Computerworld. "It was a little bit too dark, so someone shined a flashlight in there and there was a PC."

The counterfeit device was designed to log card data and the associated PIN numbers of cards used on the machine for later retrieval by hackers. This information would presumably be used to manufacture counterfeit cards that would be used to loot compromised accounts.

It's unclear how long the card skimming scam had been in operation before it was brought to a rapid close late last week. Defcon organisers notified local law enforcement officers, who took away the machine for tests.

The unknown crooks behind the scam installed their machine next to the hotel security entrance, in one of the few areas of the casino away from surveillance cameras. However they'd failed to take into account that the hotel would soon be visited by more than 8,000 security pros well versed in the ways of cybercrime, and more likely to spot such scams than the average Vegas convention goer.

ATM-related scams remain commonplace in Vegas. The US Secret Service and local law enforcement are investigating separate reports about ATM machines that debited accounts without dispensing cash. The suspected fraud came to light after conference presenter Chris Paget unsuccessfully attempted to withdraw $200 from an ATM at the Rio All-Suite Hotel and Casino last weekend, PC World reports. The ATM "whirred and chugged," according to Paget, but failed to dispense any money. Subsequent checks online revealed that Paget's account had been debited.

Other people reported the same problem, the cause of which is still unclear. Anything ranging from simple machine malfunction to malign tampering of one sort or another remain possibilities.

The particular focus on suspected ATM fraud during DefCon this year ironically follows a decision to cancel a planned talk on ATM security at Black Hat, the other security conference taking place in Vegas last week. Barnaby Jack, a security researcher at Juniper Networks, was blocked from giving his presentation after the unnamed ATM inventor involved put pressure on Juniper to delay the presentation, at least until it had time to address the reported problem. ®

The smart choice: opportunity from uncertainty

More from The Register

next story
Yorkshire cops fail to grasp principle behind BT Fon Wi-Fi network
'Prevent people that are passing by to hook up to your network', pleads plod
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
NEW, SINISTER web tracking tech fingerprints your computer by making it draw
Have you been on YouPorn lately, perhaps? White House website?
LibreSSL RNG bug fix: What's all the forking fuss about, ask devs
Blow to bit-spitter 'tis but a flesh wound, claim team
Black Hat anti-Tor talk smashed by lawyers' wrecking ball
Unmasking hidden users is too hot for Carnegie-Mellon
Attackers raid SWISS BANKS with DNS and malware bombs
'Retefe' trojan uses clever spin on old attacks to grant total control of bank accounts
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
Don't look, Snowden: Security biz chases Tails with zero-day flaws alert
Exodus vows not to sell secrets of whistleblower's favorite OS
prev story

Whitepapers

Seven Steps to Software Security
Seven practical steps you can begin to take today to secure your applications and prevent the damages a successful cyber-attack can cause.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.