Feeds

Card skimmers targeting more than ATMs, says EU

Crooks claw cash creatively, con consumers

Using blade systems to cut costs and sharpen efficiencies

Crooks are branching out beyond bank ATMs by installing card skimming devices on a payment terminals ranging from train ticket kiosks to parking meters, according to European anti-fraud experts.

At least five countries have logged skimming attacks against railway, bus or metro ticket machines, the European ATM Security Team (EAST) warns. Further attacks have been recorded against car parking meters, while a further three countries have seen skimming devices fitted to point-of-sale terminals.

Traditionally, skimming devices have had the ability to store card data, which is sometimes used in conjunction with pinhole cameras or other techniques to record users' keystrokes. Captured data is then sent to fraudsters, using mobile phone data networks. More recently crooks have adopted Bluetooth devices as a means to transmit stolen card data and corresponding PINs.

Looking further afield, EAST also reports the deployment of fake ATM fascias (placed over genuine ATMs) as part of plastic card scams in Latin America. The fake fascias include screens giving crooks the ability to display messages to victims.

Typically, marks are (falsely) informed that a terminal is "out of order" when they insert a card and attempt to withdraw cash. The fake unit, which comes with a built-in card skimmer, also contains a built-in keypad that fits over the real keypad and makes it much easier to record PINs.

Most skimming-related card fraud stems from countries that are yet to introduce chip-and-PIN cards such as the US, Brazil, Mexico, Peru and Thailand. Skimming attacks carried out in Europe are used to steal the information needed to make counterfeit cards, which are then used to make withdrawals in countries yet to adopt the EMV (short for Europay, MasterCard and Visa) standard. That's because forging a magnetic strip is simplicity itself, while cloning a chip is extremely difficult.

European banks are attempting to combat this type of fraud by introducing geo-blocking on debit and credit cards.

Crude blags involving theft of cash machines or forcing them open and looting their contents are still prevalent, EAST notes.

"Ram raids and ATM burglary were reported by nine countries," says the report. "Seven countries reported explosive gas attacks, and this form of attack appears to be increasing across Europe."

Other scams include the use of cash claws designed to trap cash withdrawals made by genuine customers. The money is not visible by the mark because it's held behind the cash slot. The ATM will log a fault but is physically unable to retrieve the cash back into the dispenser because it is trapped in the claw. Crooks return after customers have left to force the shutter open and obtain both the claw and any cash it has caught.

"Cash trapping incidents were reported by eighteen countries, with significant increases being reported by three of them," EAST reports. "Usage of the cash claw for cash trapping is spreading and this device is also being used to assist with transaction reversal fraud."

Pictures of cash claws, along with a more detailed description of this type of attack, can be found in a blog post by cybersecurity blogger Brian Krebs here. ®

The smart choice: opportunity from uncertainty

More from The Register

next story
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
Yorkshire cops fail to grasp principle behind BT Fon Wi-Fi network
'Prevent people that are passing by to hook up to your network', pleads plod
NEW, SINISTER web tracking tech fingerprints your computer by making it draw
Have you been on YouPorn lately, perhaps? White House website?
LibreSSL RNG bug fix: What's all the forking fuss about, ask devs
Blow to bit-spitter 'tis but a flesh wound, claim team
Black Hat anti-Tor talk smashed by lawyers' wrecking ball
Unmasking hidden users is too hot for Carnegie-Mellon
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
Don't look, Snowden: Security biz chases Tails with zero-day flaws alert
Exodus vows not to sell secrets of whistleblower's favorite OS
Own a Cisco modem or wireless gateway? It might be owned by someone else, too
Remote code exec in HTTP server hands kit to bad guys
prev story

Whitepapers

Seven Steps to Software Security
Seven practical steps you can begin to take today to secure your applications and prevent the damages a successful cyber-attack can cause.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.