Risk
3/10/2011
10:35 AM
George V. Hulme
George V. Hulme
Commentary
50%
50%

Watch Where You Swipe

We tend to focus attention toward online data and identity theft and forget that we can be targeted just as easily offline.

We tend to focus attention toward online data and identity theft and forget that we can be targeted just as easily offline.A couple of years ago I noticed strange, and hefty, charges were quickly racked up on one of my credit cards. I had only used that card at one restaurant in the month prior, so I had a pretty good idea where the card account data was stolen. It wasn't a big deal getting the charges removed from my account and reopening a new one. It was a couple hours on the phone and some paperwork. Done.

Fortunately, it was much easier than what had happened fifteen years ago at a gym where I often worked out at the time. In that incident, I returned to my locker only to find the neck of the combination lock sliced with bolt cutters and on the floor. My gym bag was shuffled and my wallet gone. It wasn't long before I noticed items I hadn't bought on my statements, and I started getting collection calls from accounts I hadn't opened.

Nightmare. That incident took months to clean up and a year to get my credit report back into proper shape. Only thing fortunate was that I didn't need new credit for anything that year.

Those two incidents are why I can empathize so easily with the victims of the latest batch of credit card skimming attacks in Southern California. According to prosecutors, two men face felony charges for planting card skimming devices inside several gas pumps in Los Altos and Mountain View late last year.

From the LosAltos Patch:

Deputy District Attorney Tom Flattery said Wednesday that he received several phone calls from people who stated that they had been victims of identity theft and that they had used those gas pumps.

"If you know you've been a victim and you know you frequented one of these stations, it's logical to assume that it may have been at one of these stations," he said, adding that consumers should take really good looks at their credit card statements for irregularities. "If you see small charges like $1 to $2 that could be a test charge in preparation for a big hit."

Flattery said authorities believe that some 3,600 credit card numbers collected by the skimmer had not been compromised that is, used criminally, because they remained on the card skimmers when the pair was arrested. Usually, Flattery explained, these devices just collected the numbers and then the numbers would get dumped into a computer.

While big data breaches make the headlines, small operations like this are stealing from thousands of people as they try to go about their daily business every day.

For my security and technology observations throughout the day, find me on Twitter.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-3407
Published: 2014-11-27
The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 9.3(.2) and earlier does not properly allocate memory blocks during HTTP packet handling, which allows remote attackers to cause a denial of service (memory consumption) via crafted packets, aka Bug ID CSCuq68888.

CVE-2014-4829
Published: 2014-11-27
Cross-site request forgery (CSRF) vulnerability in IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, allows remote attackers to hijack the authentication of arbitrary users for requests tha...

CVE-2014-4831
Published: 2014-11-27
IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, allow remote attackers to hijack sessions via unspecified vectors.

CVE-2014-4832
Published: 2014-11-27
IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, allow remote attackers to obtain sensitive cookie information by sniffing the network during an HTTP session.

CVE-2014-4883
Published: 2014-11-27
resolv.c in the DNS resolver in uIP, and dns.c in the DNS resolver in lwIP 1.4.1 and earlier, does not use random values for ID fields and source ports of DNS query packets, which makes it easier for man-in-the-middle attackers to conduct cache-poisoning attacks via spoofed reply packets.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?