Monday, August 11, 2008

Again, Debit Growth Far Outpaces Credit

U.S. credit card transaction and dollar-volume growth once again played second fiddle to debit, According to the latest financial reports from MasterCard Inc. and Visa Inc., U.S. debit and still-strong international growth kept the networks’ operating earnings in the black during their quarters ended June 30th.

MasterCard’s U.S. debit- purchase transactions, excluding the PIN-based Maestro brand, rose 17.8% to 1.9 billion in the quarter from 1.61 billion in the year earlier period. Over the same period, U.S. debit purchase volume rose 18.6% to $79 billion from $67 billion.

In contrast, U.S. credit and charge card purchase transactions rose only 0.8% to 1.59 billion, and credit/charge purchase volume increased just 2.8% to $142 billion.

In all, MasterCard’s U.S. credit and debit purchase transactions rose 9.4% from the corresponding year-earlier quarter to 3.49 billion. Worldwide, MasterCard’s network processed 5.22 billion transactions on MasterCard, Maestro, and Cirrus cards, up 13.6%. U.S. credit didn’t fare as badly at Visa, yet growth still fell far short of debit. U.S. debit payment transactions rose 15.8% to 4.91 billion from 4.24 billion in the year-earlier quarter.

Debit purchase volume, including that on Visa’s Interlink PIN-based network, hit $193 billion, up 16.3% from $166 billion in fiscal 2007’s second quarter.

On the credit side, U.S. payment transactions posted a 7.2% increase to 2.17 billion from the year-earlier quarter’s 2.02 billion, while payment volume rose 8.1% to $195 billion from $181 billion.

And the Password Is...(Information Card)

Information Cards (protected by a PIN) look to be a logical replacement to passwords.  Microsoft, Google and Oracle are among the founding members.  So what exactly is an information card?  Here's a brief overview from the Information Card Foundation: (ICF)

Information Cards are the digital, online equivalents of your physical identification credentials such as a drivers license, passport, credit card, club card, business card or a social greeting card. Users control the distribution of their personal information through each Information Card. Information Cards are stored in a user’s own online wallet (called a “selector”) and “handed out” with a mouse click just like a physical ID card.

Information Cards can be issued to users by organizations for general or specific use. Users can also create their own Information Cards as a shortcut to avoid the endless process of filling out web forms. But more importantly, the infastructure behind the cards allows for trusted sources (a bank, a credit union, a government office, etc.) to verify specific information (“claims”) made by a user. In other words, Information Cards give users the ability to make claims about themselves, verified by qualified 3rd parties, while using the Internet.

Here's an excerpt from an article from yesterday's NY Times "Goodbye Passwords You Aren't a Good Defense" talking more about Information Cards:

Password-based log-ons are susceptible to being compromised in any number of ways. Consider a single threat, that posed by phishers who trick us into clicking to a site designed to mimic a legitimate one in order to harvest our log-on information. Once we’ve been suckered at one site and our password purloined, it can be tried at other sites.

The solution urged by the experts is to abandon passwords — and to move to a fundamentally different model, one in which humans play little or no part in logging on. Instead, machines have a cryptographically encoded conversation to establish both parties’ authenticity, using digital keys that we, as users, have no need to see.  In short, we need a log-on system that relies on cryptography, not mnemonics.

As users, we would replace passwords with so-called information cards, icons on our screen that we select with a click to log on to a Web site. The click starts a handshake between machines that relies on hard-to-crack cryptographic code. The necessary software for creating information cards is on only about 20 percent of PCs, though that’s up from 10 percent a year ago. Windows Vista machines are equipped by default, but Windows XP, Mac and Linux machines require downloads.  And that’s only half the battle: Web site hosts must also be persuaded to adopt information-card technology for sign-ons.

It is the author of the NY Times article that we won’t make much progress on information cards in the near future because of what he calls "wasted energy and attention devoted to a large distraction, the OpenID initiative". OpenID promotes “Single Sign-On”: with it, logging on to one OpenID Web site with one password will grant entrance during that session to all Web sites that accept OpenID credentials.

Support for OpenID is conspicuously limited, however. Each of the big powers supposedly backing OpenID is glad to create an OpenID identity for visitors, which can be used at its site, but it isn’t willing to rely upon the OpenID credentials issued by others. You can’t use Microsoft-issued OpenID at Yahoo, nor Yahoo’s at Microsoft.

Why not? Because the companies see the many ways that the password-based log-on process, handled elsewhere, could be compromised. They do not want to take on the liability for mischief originating at someone else’s site.

Kim Cameron, Microsoft’s chief architect of identity, is an enthusiastic advocate of information cards, which are not only vastly more secure than a password-based security system, but are also customizable, permitting users to limit what information is released to particular sites. “I don’t like Single Sign-On,” Mr. Cameron said. “I don’t believe in Single Sign-On.”

Microsoft and Google are among the six founding companies of the Information Card Foundation, formed to promote adoption of the card technology. The presence of PayPal, which is owned by eBay, in the group is the most significant: PayPal, with its direct access to our checking accounts, will naturally be inclined to be conservative. If it becomes convinced that these cards are more secure than passwords, we should listen.

BUT perhaps information cards in certain situations are convenient to a fault, permitting anyone who happens by a PC that is momentarily unattended in an office setting to click quickly through a sign-on at a Web site holding sensitive information. This need not pose a problem, however.

“Users on shared systems can easily set up a simple PIN code to protect any card from use by other users,” Mr. Cameron said.  The PIN doesn’t return us to the Web password mess: it never leaves our machine and can’t be seen by phishers.

Logging on to a site should entail a cryptographic conversation between machines, saving us from inadvertently giving away the keys.

Sunday, August 10, 2008

Sorry Charlie...You've Been Hacked

There's been a lot of hype regarding contactless RFID cards and their security, or lack thereof.  My last post, entitled WarDriving 101 provides a good intro to the following one, which I could've called WarCarting 101


A federal judge on Saturday granted the Massachusetts  Bay Transit Authority's request for an injunction preventing three MIT students from giving a presentation about hacking smartcards used in the Boston subway system.   For the full restraining order click here


The undergraduate students had been scheduled to give a presentation Sunday afternoon at the Defcon hacker conference in Las Vegas that they had said would "describe "several attacks to completely break the CharlieCard," an RFID card that the Massachusetts Bay Transportation Authority uses on the Boston T subway line. They also planned to release card-hacking software they had created, but canceled both the presentation and the release of the software.

U.S. District Judge Douglas Woodlock on Saturday ordered the students not to provide "program, information, software code, or command that would assist another in any material way to circumvent or otherwise attack the security of the Fare Media System." Woodlock granted the MBTA's request after a hastily convened hearing in Massachusetts that took place at 8 a.m. PDT on Saturday.

The Electronic Frontier Foundation, (EFF)which is representing the students, anticipates appealing the ruling, said EFF senior staff attorney Kurt Opsahl.  EFF staff attorney Kurt Opsahl said that the temporary restraining order is "violating their First Amendment rights"; another EFF attorney said a court order pre-emptively gagging security researchers was "unprecedented."  Here's the press release from the Electronic Frontier Foundation: followed by Defcon 16's overview of the scheduled presentation:

The Anatomy of a Subway Hack:
Breaking Crypto RFID's and Magstripes of Ticketing Systems

Zack Anderson Student, MIT
RJ Ryan Student, MIT
Alessandro Chiesa Student, MIT


In this talk we go over weaknesses in common subway fare collection systems. We focus on the Boston T subway, and show how we reverse engineered the data on magstripe card, we present several attacks to completely break the CharlieCard, a MIFARE Classic smartcard used in many subways around the world, and we discuss physical security problems. We will discuss practical brute force attacks using FPGAs and how to use software-radio to read RFID cards. We survey 'human factors' that lead to weaknesses in the system, and we present a novel new method of hacking WiFi: WARCARTING. We will release several open source tools we wrote in the process of researching these attacks. With live demos, we will demonstrate how we broke these systems.

Zack Anderson is studying electrical engineering and computer science at MIT. He is an avid hardware and software hacker, and has built several systems such as an autonomous vehicle for the DARPA Grand Challenge. Zack is especially interested in the security of embedded systems and wireless communications. He has experience building and breaking CDMA cellular systems and RFID. Zack has worked for a security/intelligence firm, and has multiple patents pending. He enjoys building systems as much as he enjoys breaking them.


RJ Ryan is researcher at MIT. His longtime passion for security has resulted in a number of hacks and projects, including a steganographic cryptography protocol. RJ works on a number of technical projects ranging from computer security to operating systems, distributed computation, compilers, and computer graphics. He enjoys learning how things work, and how to make things work for him.


Alessandro Chiesa is a Junior at MIT double majoring in Theoretical Mathematics and in Electrical Engineering and Computer Science. Born and raised in Varese,Italy, he came to MIT with interests in computational algebraic geometry, machine learning, cryptography, and systems security. He has authored papers such as "Generalizing Regev's Cryptosystem", which proposes a new cryptosystem based on shortest vector problems in cyclotomic fields. He is currently working with Oracle's Database Security group.

Thursday, August 7, 2008

WarDriving 101

Earlier this week the DoJ busted the international hacking ring behind the TJMax data breach. The method used to "break-in" was simplistic, a technique called "wardriving." I wanted to learn more about it, so I googled "wardriving and jejune as it may be, I thought I'd share the following article from the London Times:

The picture of the BlueTooth WiFi Sniper Gun came from an image search
.

The charge sheet for the 11 alleged conspirators in what the US DoJ calls "the largest hacking and identity theft case ever prosecuted" identifies a technique known as wardriving.

Wardriving involves a computer user driving around searching for insecure wireless networks. All the hacker needs to steal credit card and other information from a shop is a standard laptop that picks up the signal from the wireless network in a store.

If the security on the shop's wireless network is weak, the hacker can break in within a matter of seconds in some cases — gaining access to information held by the indivudual store, such as credit card numbers, as well other information kept on the company network to which the store is connected.

Wireless networks are now extremely common in retail stores. Restaurants also use wireless terminals so that customers can pay bills with a debit card without leaving their table.

Staff in supermarkets and clothing shops carry wireless handheld devices to scan and manage stock, and many shops now also manage their entire payment systems over such networks —to avoid the hassle of moving jumbles of wires should they wish to change their layout.

Hackers who engage in wardriving will typically search for shops that use outdated security systems — or protocols — to protect their wireless networks. One of the oldest protocols, called Wired Equivalent Privacy (WEP) — which is still widely in use — can be hacked in a matter of seconds, experts said.

Modern protocols, such as Wi-fi Protected Access (WPA), and WPA2 are more resilient, but can still be successfully hacked if the shop or other outlet has not chosen effective passwords or followed other basic network safety guidelines.

"In some cases you're talking about the equivalent of locking the side gate with a suitcase padlock — it's that insecure," said Paul Vlissidis, a security expert with the Manchester-based company NCC Group.

Once a hacker has stolen the credit card and other information, he or she will typically sell it in online chatrooms where criminals gather to trade such details.

The US charge sheet accuses the alleged hackers of laundering the money using "internet-based currencies" — likely a reference to online payment systems such as e-gold, which facilititate anonymous money transfer.

The main reason that wireless networks used by retail outlets remain weak is the cost of upgrade. "If it's a supermarket that has thousands of those devices to check stock, then you're talking about a massive cost to rip out the old wireless infrastructure," said Paul Cronin, a security tester with the Reading-based company Pentura.

An alliance of credit card companies and banks is working to introduce a new standard that would increase security by requiring stores to satisfy 12 criteria before being allowed to process payments wirelessly.

The Payment Card Industry Data Security Standard (PCI DSS) — which is supported by APACS, the UK payments association — would require stores to use up-to-date encryption, install firewalls, restrict access to information kept on the network and monitor and test their networks regularly.

Wednesday, August 6, 2008

Skimming Threat Strengthens Inherent Value of HomeATM Wedgie

Credit and Debit card Skimming is becoming all the more commonplace. Fortunately for us, law enforcement is becoming more and more diligent. But will it help, can they keep up?

I believe these articles provide further insight, if not downright proof, that utilizing a personal swiping device (such as HomeATM's Wedgie) for online transactions, is "significantly safer" than swiping a card through a POS device provided by retailers in the physical world.




Another pain at the pump -- credit card skimmers
.


It's an ongoing problem nationwide -- thieves putting small devices on card readers at gas pumps to steal credit or debit card information. Steve Meissner with Arizona Weights and Measures said it hasn't really been a problem in Arizona. ``About a year ago, we did find evidence of a skimmer in one location," Meissner said, adding that he has not seen another case since.

But, he said the state is still vigilant. ``We're checking about 22,000 meters a year... Every time we check a fueling device, we open up the meter on the gas pump and look for any evidence of an illegal device like that." Meissner said some devices are easy to spot -- they're external, big and loose. Other times, they're really hard to detect. ``There are other devices that are put internally inside the gas pump, which is why we get the key from operators of the gas pump and physically look for anything," he said.

###

Customers and police agencies across the USA are dealing with another pain at the pump, thieves who install hard-to-detect electronic devices at stations to steal credit and debit card data. The skimmed data are used to create cards used at the victims' expense, says James Van Dyke, president and founder of Javelin Strategy and Research, a financial consulting firm that focuses on fraud and identity theft.

Investigations of theft related to skimming devices at gas pumps continue in Arizona, California, Washington, Nevada, Pennsylvania and Delaware, according to various police departments.

Though the most recent cases don't necessarily represent an epidemic, the Secret Service is investigating incidents across the country, says Ed Donovan, spokesman for the agency, which has financial and electronic crimes units. Skimming devices have been used for several years, most often at ATMs. Thieves increasingly target pumps because it's a cheap, easy way to steal credit and debit card information, Van Dyke says.

"Card fraud at gas pumps is a significant problem, and that's because of the unintended nature of the checkout devices," he says. "Essentially, every gas pump is an electronic cash register."

The skimming devices can be installed both inside OR outside the pump.Thieves glue a plastic sleeve, equipped with covered wires that capture data, over the pump's card reader or connect the device directly to the reader inside. The devices are molded and painted to match the machine and are small, making them hard to detect, Van Dyke says. Among recent cases:

•California: San Jose police are investigating a case that began in May, when thieves placed a skimming device at an Arco station, eventually taking more than $200,000 from up to 180 victims, says police department spokesman Jermaine Thomas. The device was on the pump for more than a month, after which the suspects retrieved the machine, Thomas says. "Your normal, average person would not even know that the skimming device is attached," he says.

• Washington: The Pierce County Sheriff's Office is investigating a case where thieves installed a skimming device at an Arco gas pump last August, leaving it there for 11 months and cleaning out at least 120 victims' bank accounts over the July 4th weekend, says sheriff's spokesman Ed Troyer. Reports of fraudulent withdrawals are still pouring in, and the number of victims could reach 250 with a total of $500,000 stolen, he says.

• Pennsylvania: State police recovered four skimming devices installed inside gas pumps at Wawa stations in Delaware, Chester, Montgomery and Bucks counties beginning in April, trooper Christopher Shoap says. He suspects more devices were used at other stations and estimates that several dozen victims have lost tens of thousands of dollars.

•Delaware: The Pennsylvania case is linked to one in Delaware, where police suspect a device was placed and later retrieved at a New Castle Wawa pump, Shoap says. The Secret Service is investigating, says Cpl. Jeff Whitmarsh of the Delaware State Police. The Secret Service would not comment because the investigation is continuing.

•Nevada: The Las Vegas Metropolitan Police Department is investigating two devices placed at gasoline pumps within the past four months, in addition to several cases where devices were placed on ATMs, says Lt. Bob Sebby of the financial crimes unit.

The combined cases total $1 million to $3.5 million stolen from hundreds of victims' accounts, Sebby says. The department is trying to prevent additional identity fraud by asking gas stations to consider placing sticker seals on the pumps that employees can check daily.

"With identify theft, it's not a matter of if you're going to be a victim, it's a matter of when," Sebby says.

###

Meanwhile...on the ATM front:

Police in Montgomery County say they need help from the public in tracking down the suspects who allegedly set up a camera and a skimmer device to record card and PIN numbers from an ATM machine at a Bethesda bank.

Investigators say they were alerted to the scheme on August 2 when a customer told employees of the Bank of America on Rockville Pike he had noticed something suspicious. Police say the man discovered that the light cover of the bank's ATM machine was lying on the counter with a small counter taped to the inside.

Officers say they believe the camera was placed inside the machine to record PIN numbers of customers who used the ATM. Further investigation revealed that a skimmer device had also been placed at the ATM, and it captured the credit and debit card numbers when customers put their cards into the machine.

Detectives say the devices were in place from about 2 p.m. to 6:20 p.m. on Saturday, August 2. Bank of America is in the process of contacting customers whose accounts may have been affected by the scheme.

Related Stories from the past 10 days:

Editorial: 'Skimmers' add insults to injuries
Crooks steal cash when you pump gas
Thieves Skim Cards at Gas Pumps
Credit card info 'skimmed' from Phila. area gas pumps
2 sought in debit card skimming thefts The News Journal
Police Issue Warning About Credit Scammers CBS 3
Updated: Wawa 'skimming' case All Around Philly
Suspects sought in skimming

Debit skimmers hit Galaxy patrons
Tips to spot a skimming device on that debit card reader

High Gas Prices to "Drive" More Shoppers Online

iCongo, Inc., a leading developer of e-business systems and software, today released the results of a consumer survey conducted on their behalf by Harris Interactive(R) that shows the surge in gasoline prices will sharply cut consumers' holiday spending and drive more shoppers online. (pun intended?)

As a result of increasing gasoline prices, nearly 3 in 4 online adults, 73 percent, expect their holiday shopping habits to change in some way, for example, by spending less on gifts (42 percent) and doing more one-stop shopping (40 percent).

Findings show more than one in three online adults (36 percent) are now more likely to shop online rather than in-person as a result of the increasing price of gasoline.

The iCongo survey also shows that nearly nine in ten online adults, 88 percent, currently shop online and, of those, the majority, 96 percent, are more likely to shop online than in-person at a store.  Here's why:
  • 69 percent of online shoppers prefer the ability to shop at any time as a reason they are more likely to shop online;
  • 60 percent said free shipping is a reason they are more likely to shop online; and,
  • 59 percent of online shoppers said lower prices drive them to shop online over in a store.
  • E-retailers frequently offer free or discounted shipping and online-only pricing to drive consumer interest in online shopping.

    For full survey results, please email your request to
    harrispoll@icongo.com.

    "Painful gas prices are hitting consumers' pocketbooks and impacting spending habits," said Irwin Kramer, founder and CEO of iCongo. "Our survey shows that 73 percent of all online adults expect their holiday shopping habits to change--a dramatic indication that gas prices are deeply impacting shoppers' attitudes." According to this data, regardless of age, gender, region of the country or income, high gas prices are driving many consumers to shop online.

But...We Need Unfair/Deceptive Practices to Be Profitable, J.P.Morgan?

I gotta kick-outta this one...let's cut to the Chase...

In May, the Federal Reserve and other regulators proposed steps to end what they called "unfair and deceptive" practices in the credit card industry. The rules aim to protect people from having their interest rates raised arbitrarily. (among other practices)

However, today came this (From JPMorgan Chase):


"The Federal Reserve's proposed rules for credit card lenders could lead to the banking industry to lose at least $10.6 billion in interest annually, JPMorgan Chase & Co. said in a letter to regulators, citing a study."


The bank said those industry losses would likely result in a nearly 12 percent increase in annual percentage rates to an average of 16.58 percent! They also said it would result in a $1.1 trillion reduction in total credit lines to consumers; and tighter standards that would stop $11 billion in new accounts from being booked each year.

Editors Note: Wait...am I getting this right? Is J.P Morgan really saying "If the Federal Reserve (in order to prevent our "arbitrary" interest rate spike in cards) steps in and attempts to END our "unfair and deceptive" credit card practices, an interest rate increase will become mandatory. Are they really saying that they "cannot afford" to do business without deceptive and unfair behavior? Or are they saying, "we'll meet you halfway...we'll get rid of the deception part, but please let us keep "unfair" or we stand to lose $10.6 billion in interest fees.
Wait...there's more:
In a letter sent Monday to the Fed's board of governors, the "Office of Thrift Supervision" and National Credit Union Administration, JPMorgan's Chase Bank subsidiary said the proposed regulation, if finalized, "is likely to have profound effects on Chase's operations and financial results."

The cumulative impact for the participating banks is at least $10.6 billion in annualized interest lost, Chase said in its letter,
signed by Associate General Counsel Andrew T. Semmelman.

On Monday, the chairman of the Senate's investigations subcommittee said he supports the Federal Reserve's proposed restrictions on credit card practices -- but that he believes there should be more.
Sen. Carl Levin, D-Mich., wrote in a 13-page letter to the Fed that it should expand its rules to end or restrict such practices as charging interest for debt paid on time; interest on transaction fees; fees levied on consumers paying their bills on time; and billing amounts that force consumers to pay four or five times their original debt.

Back in March, JPMorgan Chase, at the behest of the U.S. government, bought the ailing investment bank Bear Stearns Cos. when it appeared to be near collapse.

Editors Note: Kind of gives new meaning to the term "conflict of interest" doesn't it? It'll be interesting, to say the least, to watch how this turns out.

Prediction..not good for consumers. Not good for the credit card companies.


Related: Chuck Jaffe writes for MarketWatch:
Cost of Credit Card Reform? Pricey

Tuesday, August 5, 2008

Credit/Debit Hackers of 40 million Cards "Sniffed Out" by DOJ

Eleven Indictments in 40 Million Card TJ Max Data Breach





The US Department of Justice has announced that "eleven perpetrators allegedly involved in the hacking of nine major U.S. retailers and the theft and sale of more than 40 million credit and debit card numbers have been charged with numerous crimes, including conspiracy, computer intrusion, fraud and identity theft.  The scheme is believed to constitute the largest hacking and identity theft case ever prosecuted by the Department of Justice."



Three of the defendants are U.S. citizens, one is from Estonia, three are from Ukraine, two are from the People's Republic of China and one is from Belarus. One individual is only known by an alias online, and his place of origin is unknown.



In an indictment returned on Aug. 5, 2008, by a federal grand jury in Boston, Albert "Segvec" Gonzalez, of Miami, was charged with computer fraud, wire fraud, access device fraud, aggravated identity theft and conspiracy for his role in the scheme. Criminal informations were also released today in Boston on related charges against Christopher Scott and Damon Patrick Toey, both of Miami.



The Boston indictment alleges that during the course of the sophisticated conspiracy, Gonzalez and his co-conspirators obtained the credit and debit card numbers by "wardriving" and hacking into the wireless computer networks of major retailers -- including TJX Companies, BJ's Wholesale Club, OfficeMax, Boston Market, Barnes & Noble, Sports Authority, Forever 21 and DSW.



The indictment alleges that after they collected the data, the conspirators concealed the data in encrypted computer servers that they controlled in Eastern Europe and the United States. They allegedly sold some of the credit and debit card numbers, via the Internet, to other criminals in the United States and Eastern Europe. The stolen numbers were "cashed out" by encoding card numbers on the magnetic strips of blank cards. The defendants then used these cards to withdraw tens of thousands of dollars at a time from ATMs. Gonzalez and others were allegedly able to conceal and launder their fraud proceeds by using anonymous Internet-based currencies both within the United States and abroad, and by channeling funds through bank accounts in Eastern Europe.



Once inside the networks, they installed "sniffer" programs that would capture card numbers, as well as password and account information, as they moved through the retailers' credit and debit processing networks.



Gonzalez was previously arrested by the Secret Service in 2003 for access device fraud. During the course of this investigation, the Secret Service discovered that Gonzalez, who was working as a confidential informant for the agency, was criminally involved in the case. Because of the size and scope of his criminal activity, Gonzalez faces a maximum penalty of life in prison if he is convicted of all the charges alleged in the Boston indictment.


Also today, indictments were unsealed in San Diego against scheme participant Maksym "Maksik" Yastremskiy, of Kharkov, Ukraine, and Aleksandr "Jonny Hell" Suvorov, of Sillamae, Estonia. The indictments charge the defendants with crimes related to the sale of the stolen credit card data that Gonzalez and others illegally obtained, as well as additional stolen credit card data. Suvorov is charged with conspiracy to possess unauthorized access devices, possession of unauthorized access devices, trafficking in unauthorized access devices, identity theft, aggravated identity theft, and aiding and abetting. Yastremskiy is charged with trafficking in unauthorized access devices, identity theft, aggravated identity theft and conspiracy to launder monetary instruments. The indictment also contains a forfeiture allegation.


In addition, an indictment against Hung-Ming Chiu and Zhi Zhi Wang, both of the People's Republic of China, and a person known only by the online nickname "Delpiero," was also unsealed in San Diego today. Chiu, Wang and Delpiero are charged with conspiracy to possess unauthorized access devices, trafficking in unauthorized access devices, trafficking in counterfeit access devices, possession of unauthorized access devices, aggravated identity theft, and aiding and abetting. Also in San Diego, Sergey Pavolvich, of Belarus, and Dzmitry Burak and Sergey Storchak, both of Ukraine, were charged in a criminal complaint with conspiracy to traffic in unauthorized access devices. All are believed to be foreign nationals residing outside of the United States.


The San Diego charges allege that Yastremskiy, Suvorov, Chiu, Wang, Delpiero, Pavolvich, Burak and Storchak operated an international stolen credit and debit card distribution ring with operations from Ukraine, Belarus, Estonia, the People's Republic of China, the Philippines and Thailand. The indictments allege that each of the defendants sold stolen credit and debit card information for personal gain. For example, the indictment of Yastremskiy alleges that he received proceeds exceeding $11 million from this criminal activity. These indictments and complaints are the result of a three-year undercover investigation conducted out of the San Diego Field Office of the U.S. Secret Service.


In May 2008, Gonzalez, Suvorov and Yastremskiy also were charged in a related indictment in the Eastern District of New York. The New York charges allege that the trio was engaged in a sophisticated scheme to hack into computer networks run by the Dave & Buster's restaurant chain, and stole credit and debit card numbers from at least 11 locations. Specifically, the indictment alleges that the defendants gained unauthorized access to the cash register terminals and installed at each restaurant a "packet sniffer," a computer code designed to capture communications on a computer network. The packet sniffer was configured to capture credit and debit card numbers as this information was processed by the restaurants. At one restaurant location, the packet sniffer captured data for approximately 5,000 credit and debit cards, eventually causing losses of at least $600,000 to the financial institutions that issued the credit and debit cards.


Gonzalez is currently in pre-trial confinement on the New York charges. Based upon the San Diego charges, Turkish officials apprehended Yastremskiy in July 2007 in Turkey when he traveled there on vacation. He has been in confinement since then in Turkey, pending the resolution of related Turkish charges, and the United States has made a formal request for his extradition. At the request of the Department of Justice, Suvorov was apprehended by the German Federal Police in Frankfurt in March 2008 on the San Diego charges when he traveled there on vacation. He is currently in confinement pending the resolution of extradition proceedings.


"So far as we know, this is the single largest and most complex identity theft case ever charged in this country," said Attorney General Mukasey. "It highlights the efforts of the Justice Department to fight this pernicious crime and shows that, with the cooperation of our law enforcement partners around the world, we can identify, charge and apprehend even the most sophisticated international computer hackers."


"While technology has made our lives much easier it has also created new vulnerabilities. This case clearly shows how strokes on a keyboard with a criminal purpose can have costly results. Consumers, companies and governments from around the world must further develop ways to protect our sensitive personal and business information and detect those, whether here or abroad, that conspire to exploit technology for criminal gain," said U.S. Attorney Michael J. Sullivan.


"These prosecutions demonstrate that, through coordinated commitment, the United States Secret Service and the Department of Justice will penetrate and prosecute hacker organizations, wherever based and however sophisticated. The United States Attorney's Office for the Southern District of California is especially gratified that the work of the San Diego field office of the Secret Service contributed to an unprecedented effort to dismantle this international criminal enterprise," said Karen P. Hewitt, U.S. Attorney for the Southern District of California.


"Computer hacking and identity theft pose serious risks to our commercial, personal and financial security," said U.S. Attorney for the Eastern District of New York Benton J. Campbell. "Hackers who reach into our country from abroad will find no refuge from the reach of U.S. criminal justice."


"Technology has forever changed the way commerce is conducted, virtually erasing geographic boundaries," said U.S. Secret Service Director Mark Sullivan. "While these advances and the global nature of cyber crime continue to have a profound impact on our financial crimes investigations, this case demonstrates how combining law enforcement resources throughout the world sends a strong message to criminals that they will be pursued and prosecuted no matter where they reside."


"The Internal Revenue Service Criminal Investigation Division recommends charges in numerous types of financial crimes," said Internal Revenue Service Criminal Investigation (IRS-CI) Chief Eileen Mayer. "Today's indictment is the result of a strong law enforcement partnership that brings together the necessary skills to follow alleged criminal activity from cyberspace to bank accounts. We are committed to the government's efforts to stop this type of corruptive activity."


These cases are being prosecuted by Assistant U.S. Attorney Stephen Heymann of the District of Massachusetts, Assistant U.S. Attorney Orlando Gutierrez of the Southern District of California, Assistant U.S. Attorney Will Campos of the Eastern District of New York, and by Senior Counsel Kimberly Kiefer Peretti, and Trial Attorneys Jenny Ellickson and Evan Williams of the Criminal Division's Computer Crime & Intellectual Property Section. The Criminal Division's Office of International Affairs provided extensive assistance related to extradition matters. All of theses cases are being investigated by the U.S. Secret Service. The IRS-CI provided significant investigatory assistance in the Boston case.

55% of U.K"s eCommerce Not U.K. Consumers

Online retailers in the UK are benefiting from the wide use of English in the online world, says a new report from payment processor Pago eTransaction Services. 55% of sales at UK online retail sites are to foreigners.   By contrast, less than 5% of sales at German sites are to foreigners.



The same report, which analyzes online shopping behavior across Europe, confirms that hard-working Germans aren’t frittering away their work days at retail sites. The peak period for online shopping in Germany is 8 to 10 p.m., while in the UK it’s 2 to 4 p.m.



At UK sites, nearly a third of international customers are from countries outside Europe, especially the USA and Asia.



The 2008 Pago Report is the seventh edition of “Trends in E-commerce Purchasing and Payment Behaviour Based on Real Transactions.”   It analyzes European online consumer and payment behavior, and non-payment risks and trends in e-commerce. Analysis is based on 30 million transactions processed by Cologne-based Pago from e-commerce sites.



Other data from the report:


• The most active online consumers, in order, are British, German, French and Irish.



• German online consumers make about one-third of their purchases between October and December, while UK consumers make less than 10% of their purchases during that period. The peak time for British consumers to buy online is between May and September.



• 20% of all weekly transactions are executed in the UK on Saturdays or Sundays. In comparison, consumers outside the UK and Germany account for 26% of their purchases over the weekends.



• German consumers still pay for two out of three purchases with payment methods other than the credit card. Consumers in UK and from the rest of Europe and non-European customers use credit card payment for over 90% of their online purchases.



“E-commerce is still a black box for many. The Pago Report attempts to shed light on the matter,” says Markus Weber, Pago eTransaction Services GmbH’s managing director. “In contrast to all other studies which are based on polls, the Pago Report is unique. We analyze real-life purchase transactions processed by thousands of European merchants through the Pago platform. This gives a valid picture of e-commerce which is not only interesting for experts and researchers but also provides European merchants valuable information to assist in their entry into this promising market.”



In other U.K. eCommerce News, results from a new survey conducted by software firm Maginus, suggested that 76 per cent of online retailers have seen higher sales in the last year, with almost half of these seeing an increase in excess of 20 per cent.



Furthermore, those who utilise more than one sales channel have seen the greatest revenue increases - 84 per cent of retailers said they experienced higher sales from customers adopting a multi-channel approach than from those who use only one medium.  About 76 per cent of retailers also said they had plans to redesign their existing e-commerce website in the next year.



Russell Dorset, sales and marketing director at Maginus, said that retailers should also make preparations to cope with higher traffic.  "Slow server response or downtime on an e-commerce website may result in a lost sale, or even worse a poor customer experience may mean a customer never visit[s] your site again," he remarked. Over half of retailers are considering implementing user-generated content such as reviews into their e-commerce portals, according to a report released by E-consultancy last year.

Ireland's E-Commerce Predicted to Grow 50% from Last Year

Trend seems to be developing "everywhere"



A leading Irish ecommerce firm has predicted that the number of consumers shopping online this Christmas could increase by as much as 50% in comparison to the same period last year.



Editor's Note: For more information on the development of ecommerce in Ireland, click here.





Magico.ie says that although traditional high-street retail activity is suffering a downturn, Internet sales in Ireland are likely to smash all previous records this year as more and more price-conscious and time-poor consumers do their festive shopping online.



The company warned, however, that the Irish retail sector had not fully explored the potential of the online shopping market and was losing out on potential business to competitors throughout the world.  It indicated that many Irish small and medium enterprises needed to adapt to the growing trend among consumers who were opting to order their gifts from the comfort of their own home.



‘There is no doubt that the Internet has transformed the way Irish consumers shop and interact with the companies from which they buy’, commented Mr. Paul McGurran, Director of ecommerce, Magico.ie.  He explained, ‘Consumers, as they become more Internet-savvy, are using the Web to research gift purchases in the lead up to Christmas. Once they have narrowed down their selection many shoppers will actually visit numerous stores based on this research. Therefore, for a certain category of shopper the Internet is the first place they look prior to making a store visit.’



Mr. McGurran added that the increase in online retail activity was stimulated by numerous other factors, including time-poor consumers, greater broadband penetration across Ireland and Irish people living abroad.  ‘There is a growing tendency for shoppers to leave Christmas gift buying later into the festive season and due to time pressures many will purchase online. This option gives last minute shoppers a wide selection of possible gifts, often coming with a gift-wrapping service as extra. The online shop also takes on the role of shipping items onwards to the recipient’, said Mr. McGurran.  He continued, ‘Furthermore, many Irish abroad find the Web the obvious place to do their Christmas shopping for family still based in Ireland. This works both ways - some ex-pats will go online and use Irish based online shops to get attractive shipping rates, and conversely some Irish based consumers with family abroad may also send gifts via local online shops to friends overseas.’



The increase in shoppers using the Internet to purchase Christmas gifts is not an Irish phenomenon, with similar trends being experienced throughout much of Europe. Research shows that increasing numbers of people spend more time researching and buying online in the run-up to Christmas in comparison to those who do the same on the high street.



In the UK, the IMRG Capgemini e-Retail Sales Index claims there was a 65% increase in the numbers shopping online last Christmas compared the 2006 festive season. In recent years, the Royal Mail has had to employ extra staff to cope with the increasing volumes of mail that has arisen as a result of increased online purchases.



Commenting on the wide-ranging benefits for retailers that trade online, Mr. McGurran said, ‘Once a retailer starts trading online they immediately open up their shop to consumers beyond their natural catchment area. We notice that many of Magico’s clients are getting Web orders from London, Berlin, Dublin, Cork and from remote parts of Ireland. Often orders come in from towns and regions where the retailer does not have a physical retail presence.’



He pointed out that companies that had expanded their business into the online market were also experiencing an increased footfall on their premises. Mr. McGurran stated, ‘Both sides of the business benefit each other because a lot of people browse at home and come in to buy and other people go to the stores and then buy on the Internet. However, many Irish retailers have yet to realise this and are unknowingly denying themselves profits at the most lucrative time of the year.’



‘Irish businesses need to sit up and take notice of the steady growth in retailing via the Internet in the run up to and during the Christmas period. With the much talked of slowdown in the Irish economy and an increasingly price conscious consumer, Irish retailers really have no option but to invest in their own ecommerce and online sales store’, concluded Mr. McGurran.



Magico.ie was established in 1999 and currently employs 13 people at its headquarters in Ennis, County Clare. Its current client base includes Fujipix.ie, The Bag Shop, Smyths Toys, Irish Auctioneers & Valuers Institute, Evergreen Healthfood, Munster Rugby Supporters Club, Freshways Sandwiches, Sisk Builders and Fitzpatrick Design Hotels. The Magico.ie team consists of industry experts who have worked on large Irish and overseas ICT projects with partners such as IBM, Microsoft, Tesco.com, Ireland Online, Bank of Ireland Asset Management, and many more.  For more log on to www.magico.ie.

E-commerce Is Outpacing Bricks and Mortar

BY JACK G. HARDY


Q: I've been told that Internet retailers are growing faster than traditional ''bricks and mortar'' stores. Is this true?



A: Yes, according to the U.S. Commerce Department: ``Total retail sales (excluding petroleum, autos and restaurants) grew 3.7 percent last year. Retail stores grew 3.1 percent (one-quarter of a percent after inflation). By comparison, e-retailing grew 22 percent and remained by far the fastest-growing component of the nation's retail economy.''



Forrester Research (Forrester.com), an independent technology and market-research company, points out: ``U.S. online retail reached $175 billion in 2007 and is projected to grow to $335 billion by 2012.



Business-to-consumer (B2C) eCommerce continues its double-digit year-over-year growth rate, in part because sales are shifting away from stores and in part because online shoppers are less sensitive to adverse economic conditions than the average U.S. consumer.''



eMarketer.com forecasts: ``B2C e-commerce sales in Asia and the Pacific Area will grow at a 23.3 percent annual rate, reaching $168.7 billion by 2011. Japan is currently the largest market, by far, and South Korea ranks second. But by 2011 both will lose share to two up-and-comers -- China and India.''



Here's info from China Internet Network Information Center's Survey Report on Online Shopping in China 2008. They say, ''The total amount of online shopping in 19 big cities in China reached $2.35 billion in the first half of 2008.'' More than 40 percent of the online buyers surveyed shop online at least once a month.



India's largest online retailer, FutureBazaar.com, is a subsidiary of FutureGroup, a $1.2 billion holding company that operates Pantaloon Retail, the country's largest retailer.



You'll spot many valuable differences in marketing techniques. CEO Sankersen Banerjee reports: 'A full 45 percent of our orders come from outside our large metropolitan areas. Local couriers deliver packages since India's postal system only accepts documents. Address standardization is a major problem. A typical address might read something like `The apartment above the store on the corner.' ''



An economic boom in Brazil is changing the lives of millions. Wal-Mart opened its first store in Sao Paulo during 1995 and now has 152 stores in 14 states. Their sales in Brazil have grown at more than twice the pace of sales in the United States, reaching $9.04 billion in 2007. Now they're plunging into eCommerce with plans to invest $722.8 million to keep up with country's fast-growing consumer demand.



How about you? Your brightest idea will fail to attract profitable revenues if you fail to create an eCommerce store that provides uninterrupted shopping with an assurance of a secure online transaction.



There's an African proverb that encourages learning: Every morning in Africa, a gazelle wakes up. It knows it must run faster than the fastest lion or it will be killed. Every morning a lion wakes up. It knows it must outrun the slowest gazelle or it will starve to death. It doesn't matter if you are a lion or a gazelle. When the sun comes up, you better start running.



So, how fast are you running?
Special to The Miami Herald

Sunday, August 3, 2008

HomeATM Transactions...Eminently More Secure than Bricks and Mortar

Here's followup to a posting made to the HomeATM blog last May: "Supermarket ATM/Reader Rigged with Illicit Scanner"  regarding Lunardi's Supermarket in Los Gatos...



A former employee of Lunardi’s Supermarket in Los Gatos has been arrested on charges he was involved in a scam stealing thousands of dollars from store customers.  According to the Mercury News, Raymond Kurt Fisher, 37, was taken into custody Thursday night on burglary, conspiracy and drunken driving charges.



During the time he worked at Lunardi’s, police say Fisher installed an illegal debit card reader and stole both customers’ identification and pin numbers. Nearly $300,000 were stolen from at least 250 customers' bank accounts. Fisher is being held on $1 million bail. Authorities are continuing to investigate whether or not Fisher may have had accomplices in Southern California where most of the money was stolen.



"Scanner tampering has long been a subject of concern for security researchers, who have demonstrated the ease of ATM machine hacks, as well as of smart card scanners for physical security"



Editor's Note: Credit or debit card skimming is a real threat. Most think that credit/debit card fraud only happens online, which is simply not true.  People should trust online purchases more than they do bricks and mortar location purchases.



When you "hand your card over" to a complete stranger, all that person needs is a credit/debit card swiper to save the information from the magnetic strip on the back into a memory chip. Now they have all the information they need to create a fake credit card.  I'm surprised we haven't seen more incidents involving restaurants.  Not only do you "hand it over" but the wait/er/tress walks away with it and often doesn't return for 5-10 minutes...plenty of time to accomplish a hack-attack.



It doesn't stop there either, as there has been several instances whereby a tech savy criminal equips ATM machines with a card skimmer (see picture on left) and a video camera to record your PIN.



HomeATM's PIN-Based Online ePayment platform will transform online transactions in such a way as to not only make them  the most secure on the web, but eminently more secure than those transactions processed at brick and mortar locations.



Disqus for ePayment News