Feeds

Australian cops bust Romanian credit card thieves

Wrestler questioned after RDP SNAFU and two vulns lead to 500k card heist

High performance access to file storage

Australia's Federal Police (AFP) has triumphantly announced it has brought a gang of Romanian credit card fraudsters to heel, but not before the criminals purloined half a million credit card numbers from small Australian retailers.

Detective superintendent Brad Marden, the AFP's national co-ordinator for cybercrime operations, told The Register the gang targeted small retailers likely to be ignorant of security and used three techniques to pull of the heist.

The first was using remote desktop management software to infiltrate retailers' PCs, an exploit made possible by the fact whoever installed it had not changed the default passwords.

"The stores relied on local consultants who they were not experts on PCI-DSS, they just wanted to set up a simple small business network," Marden explained. That left RDP ignored and open to attack.

The second issue was un-patched point of sale software.

The third vulnerability that made the attack possible was an insecure point-of-sale PIN pad that Marden said was in the process of being addressed by banks, which issue the devices.

Once attackers were able to access PCs through RDP they were then able to operate the point of sale software and access credit card numbers collected from the PIN pads.

Marden said 46 of the 100 PCs known to have been hit offered sufficient evidence of the source of the hacking and that Australia's banks gathered evidence to help the force pursue the case.

Both vulnerabilities have since been addressed and an education campaign has commenced to inform small retailers about the need to update their software and hardware.

The gang came to the AFP's attention in June 2011 and the revelation of its activities set in motion a 13-nation effort that yesterday culminated in the detention of 16 people, among them champion Graeco-Roman wrestler and mixed martial arts practitioner Gheorghe 'The Carpathian Bear' Ignat, according to the ABC.

Georghe 'The Carpathian Bear' Ignat

Source: Wikipedia

The Carpathian Bear was not one of seven people arrested over the matter, which saw $AUD30m of purchases made with purloined credit card numbers. Those transactions took place around the world.

The AFP says those purchases were made with 30,000 credit cards, but that the gang managed to get its hands on half a million.

Australian financial institutions have made sure punters aren't out of pocket, refunding them for fraudulent purchases.

The news may not be as good for the retailers, as contracts offered by banks down under can make them liable for fraudulent transactions if they've not taken all requisite safeguards to protect credit cards. ®

High performance access to file storage

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
OpenSSL Heartbleed: Bloody nose for open-source bleeding hearts
Bloke behind the cockup says not enough people are helping crucial crypto project
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
Heartbleed exploit, inoculation, both released
File under 'this is going to hurt you more than it hurts me'
Bad PUPPY: Undead Windows XP deposits fresh scamware on lawn
Installing random interwebs shiz will bork your zombie box
Experian subsidiary faces MEGA-PROBE for 'selling consumer data to fraudster'
US attorneys general roll up sleeves, snap on gloves
prev story

Whitepapers

Mainstay ROI - Does application security pay?
In this whitepaper learn how you and your enterprise might benefit from better software security.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.