Feeds

Teensy card skimmers found in gullets of ATMs

Hi-tech fraudsters treading more softly, but gas still yielding bang for buck

The essential guide to IT transformation

A series of tiny and sometimes transparent card-skimming devices have been detected in ATMs across Europe, researchers say.

Boffins with the European ATM Security Team (EAST) have plucked out and displayed some clever thumb-sized skimmers that hide from victims' view by fitting in cash terminals' gullets.

The devices paraded in the EAST report European Fraud Update for 2014 (subscription required) were designed for NCR machines and contained pinhole spy cameras which together with the skimmer would provide felons with the magnetic stripe data and PINs required to replicate the cards.

One of the internal skimmers ditched the typical green fascade opting for a translucent colour, making it more difficult to spot.

Developers of ATM skimmers were at times ingenious in their bid to evade detection. KrebsonSecurity reported one style of skimmer that used audio waves to transmit captured card details which could then be decoded.

Use of mobile communications capabilities is also becoming more popular with skimmers, as it liberates fraudsters from the need to return to hijacked ATMs in order to retrieve fleeced cards or the data they bear.

Cruder cash claws, or cash trapping, still remained popular with thieves who inserted the devices to jam cash dispensers so that money can be picked up later.

The report reflected findings gathered at a meeting at the European Cybercrime Centre (EC3) in the Hague last month. The mini-skimmers were reported in one unnamed European country while others said skimmers were being left in ATMs for longer, between four to five days on average.

Chip and PIN credit cards were deployed in most G20 countries including Australia and the UK which made skimming more complex and expensive for fraudsters. However ATMs still supported outdated and vulnerable magnetic stripe reader cards due to slow adoption in the US where losses were highest, according to the report.

Eight countries reported attacks against unattended payment terminals at petrol stations and six had attacks targeting point-of-sale devices. Fraudsters had even removed ATMs returning it only after modifying the machine.

Brutish ram raids and ATM burglary were down in 10 countries with three large gangs busted by law enforcement. Explosive attacks however were on the rise with eight countries reporting the use of gas attacks and two having cash machines blown up with solid explosives.

The EC3 played a role in four large cross-border busts on criminal fraud gangs targeting online transactions, airlines, ATMs and document fraud. "In many cases the criminals transferred stolen funds to unregistered pre-paid cards for cash withdrawal at ATMs," the organisation said. ®

Next gen security for virtualised datacentres

More from The Register

next story
Ice cream headache as black hat hacks sack Dairy Queen
I scream, you scream, we all scream 'DATA BREACH'!
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
Scratched PC-dispatch patch patched, hatched in batch rematch
Windows security update fixed after triggering blue screens (and screams) of death
Researchers camouflage haxxor traps with fake application traffic
Honeypots sweetened to resemble actual workloads, complete with 'secure' logins
Attack flogged through shiny-clicky social media buttons
66,000 users popped by malicious Flash fudging add-on
New Snowden leak: How NSA shared 850-billion-plus metadata records
'Federated search' spaffed info all over Five Eyes chums
Three quarters of South Korea popped in online gaming raids
Records used to plunder game items, sold off to low lifes
Oz fed police in PDF redaction SNAFU
Give us your metadata, we'll publish your data
prev story

Whitepapers

5 things you didn’t know about cloud backup
IT departments are embracing cloud backup, but there’s a lot you need to know before choosing a service provider. Learn all the critical things you need to know.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Backing up Big Data
Solving backup challenges and “protect everything from everywhere,” as we move into the era of big data management and the adoption of BYOD.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?