Every little helps chip-and-pin thieves
By Davey Winder in Editorial
Posted in Data Protection, Blog, e-commerce on
Blimey, just as I was about to leave for the regular weekly family supermarket hike to Tesco I have to go and read this rather disturbing news story from someone whose opinion on matters ITsec related I value very highly indeed.
Graham Cluley first got wind of the fact that there might be something fishy going on at the supermarket checkout a couple of months back, following a number of reports from local newspaper journalists asking if he knew anything about credit card fraud at the supermarket. It seems that readers of local newspapers had been getting in touch to suggest particular supermarket branches had been involved in some kind of chip and pin fraud.
Now the story has exploded into the national newspapers, with the The Telegraph reporting how hundreds of the chip and pin payment machines used in supermarkets across Europe have been tampered with to steal your credit card data.
OK, so nothing new in the old double swipe, or the false front card reader for ATM machines and even the odd bit of WiFi phreakery to do this sort of thing. But this is different, this the reports suggest, involves the terminals you use at the checkout actually having been tampered with before they shipped. Internally, so that there is no way of telling from an external examination that the device is compromised.
The head of the US National Counter Intelligence Executive warns that suspect devices have been shipped to Britain, Belgium, Denmark, Ireland, and the Netherlands. All with hidden hardware that can transmit card data via the mobile phone network to the criminal ring behind the scam based in Lahore, Pakistan.
Amongst the supermarkets said to have been affected in the UK are market leaders Tesco, Asda and Sainsbury’s. Graham Cluley says that supermarkets are now “weighing chip-and-pin devices to determine if they were compromised or not, as affected machines weighed three to four ounces heavier.”
Perhaps the most worrying of all is that this time the thieves have been clever. Patient and clever. They did not cash in on the stolen data immediately, as is the usual pattern of such things, but instead waited a couple of months to make tracking back the root of the data loss that much harder.
Cluley says that buying goods in a respected supermarket should be safe, however he does warn that “Retailers are going to have to do more in future to ensure the integrity of their payment devices is utterly without question, and to guard the supply of such devices from factory to supermarket checkout, or risk losing the confidence of their customers.”
It is also distrubing as it means that although previous news reports have suggested that credit card crime has been driven overseas, that the UK is actually still at risk.
Comment by Roger - October 13, 2008 on 9:58 am
Such crimes would be prevented if banks use Card Key Code system described on website www.xwave.co.uk
Virtually all fraud crimes will be a thing of past if banks make signature and PIN systems reliable as proposed.
Comment by Mike Russell - October 14, 2008 on 11:57 am
If you follow to the video, you see, or rather hear, the problem; “Banks & institutions refuse to even listen.” No doubt there are people whose reputations sit on the current system. Were it to be demonstrated to be woefully inadequate (we all know it is..) then these, well-placed individuals would lose face. That will never happen.
Make a comment
Tag cloud
Archives
- November 2008
- October 2008
- September 2008
- August 2008
- July 2008
- June 2008
- May 2008
- April 2008
- March 2008
- February 2008
- January 2008
- December 2007
- November 2007
- October 2007
- September 2007
- August 2007
- July 2007
- June 2007
- May 2007
- April 2007
- March 2007
- February 2007
- January 2007
- December 2006
- November 2006
- October 2006
- September 2006
- August 2006
Most commented posts
- Cuil frozen out: market share drops to next to nothing
20 comments
- Windows XP: the invincible OS
- Gatecrashing the WiFi hotspot party
- The 24 year old software that is still going strong
- Home workers are sick
- Big Brother Apple
- Spear phishing Catch 22 for Salesforce.com
- Dumbest phisher in history revealed
- Is BT misleading consumers with Option 2 broadband?
- Why ecommerce fails
Highest Rated Blog Posts
- Why ecommerce fails (100%)
- Betting on Hubdub technology (100%)
- Chinese whispers as government implicated in UK hack attacks (100%)
- Crimeware toolkit targets 10,000 trusted sites (100%)
- Black Hat risk to migrating VMs (100%)
- Tough on cyber crime, tough on the causes of cyber crime (100%)
- Firefox 3, Beta 4, Enhancements 900, Tested 5 (100%)
- Slowly slowly catchee Government IT monkey (100%)
- Who needs another set of web standards? (100%)
- The 6.5 billion quid hello (100%)

