Stolen credit card details - yours for a fiver online
By Reuters
Posted on 15 Jul 2008 at 11:21
Prices charged by cybercriminals selling hacked bank and credit card details have fallen sharply as the volume of data on offer has soared, a new report says.
Researchers for Finjan, a web security firm, claims the high volumes traded had led to bank and credit card information becoming "commoditised" - account details with PIN codes that once fetched £50 or more each might now go for £5 or £10.
In its latest quarterly survey of web trends, the California-based company says cybercrime had evolved into "a major shadow economy ruled by business rules and logic that closely mimics the legitimate business world".
Finjan's Israel-based chief technology officer, Yuval Ben-Itzhak, says that new types of stolen data are now commanding a premium, such as patient healthcare information that can be used for insurance fraud or to illicitly acquire and sell medicines.
Other premium data includes business information, company personnel files and intercepted commercial emails.
Mafia style
The Finjan report, partly based on contacts the company established with five groups trading online in stolen data, described a Mafia-type cybercrime hierarchy in which bosses operate as business entrepreneurs and typically leave the actual online attacks to underlings.
An "underboss", or second-in-command, provides the Trojan infiltration software for launching attacks. The workforce that carries these out is paid according to the rate of infections achieved and the country of origin of the infected computers.
"Resellers" then trade the hacked financial data, in the same way that a criminal "fence" disposes of stolen goods.
In online exchanges with resellers, Finjan researchers were offered a menu of stolen data, with platinum, gold and corporate card details commanding the highest prices.
Sellers promised the data was "fresh" and one even offered a 48-hour guarantee to supply new details if those originally bought were rejected by payment systems as stolen cards.
"It's like in the regular business world - when you buy a good and it doesn't work, you go back and you want to replace it," says Ben-Itzhak.
"It indicates a competitive environment... They need to build reputation, they want to show they're providing high quality data for your money so you can go back and buy from them rather than go to the other groups."
Ben-Itzhak predicts banks, which until now have shouldered the burden of compensating people whose data are hacked, would seek to put some of the onus for security on the customer.
"So far the banks are not mandating the end-user to have some sort of security on their desktop. They're taking the risk, better to say they're paying the risk, when your account has been compromised," he claims.
"However what we noticed recently is the volume increased significantly and the banks are starting to ask the question: did you install something or do you have something running on your desktop?
"The banks will start to ask questions of the end-users and put some responsibility at least on them."
From around the web
This is scary stuff!
With identity fraud on the increase you just have to be so careful online now. It's worth making sure that you regularly update your virus protection software and check your credit report.
There are some other great tips for preventing identity theft at www.whichcreditreport.co.uk/identity-theft.html
It makes interesting reading!
By jemima on 2 May 2011 ![]()
advertisement
- Chrome's shine getting lost in translation
- BytePac: the cardboard hard disk enclosure
- How tech loosens our grip on reality
- Hokum watch: Safer Internet Day
- Why I'm deleting Adobe from my PC
- Prepare to be patronised: it's Safer Internet Day
- Dear Sony, Samsung and every other tech company in the world: stop trying to be Apple
- Will Apple's Final Cut Pro X update placate the pros?
- Smartr Contacts for iPhone review
- Switching to Office 365's Outlook Web App
- Why virtualisation hasn't slowed the growth of data
- How to make Google AdWords work for your business
- The curse of sloppily written software
- Paying for your crimes with Bitcoin
- Behind the scenes: tech support for Formula 1
- The security risk of fat fingers
- Why Windows Phone 7 isn't quite ready for business
- When will Microsoft stop fiddling with Windows 8?
- Flash down the pan?
- Metro Style apps vs desktop applications
advertisement
