Risk
3/10/2011
10:35 AM
George V. Hulme
George V. Hulme
Commentary
50%
50%

Watch Where You Swipe

We tend to focus attention toward online data and identity theft and forget that we can be targeted just as easily offline.

We tend to focus attention toward online data and identity theft and forget that we can be targeted just as easily offline.A couple of years ago I noticed strange, and hefty, charges were quickly racked up on one of my credit cards. I had only used that card at one restaurant in the month prior, so I had a pretty good idea where the card account data was stolen. It wasn't a big deal getting the charges removed from my account and reopening a new one. It was a couple hours on the phone and some paperwork. Done.

Fortunately, it was much easier than what had happened fifteen years ago at a gym where I often worked out at the time. In that incident, I returned to my locker only to find the neck of the combination lock sliced with bolt cutters and on the floor. My gym bag was shuffled and my wallet gone. It wasn't long before I noticed items I hadn't bought on my statements, and I started getting collection calls from accounts I hadn't opened.

Nightmare. That incident took months to clean up and a year to get my credit report back into proper shape. Only thing fortunate was that I didn't need new credit for anything that year.

Those two incidents are why I can empathize so easily with the victims of the latest batch of credit card skimming attacks in Southern California. According to prosecutors, two men face felony charges for planting card skimming devices inside several gas pumps in Los Altos and Mountain View late last year.

From the LosAltos Patch:

Deputy District Attorney Tom Flattery said Wednesday that he received several phone calls from people who stated that they had been victims of identity theft and that they had used those gas pumps.

"If you know you've been a victim and you know you frequented one of these stations, it's logical to assume that it may have been at one of these stations," he said, adding that consumers should take really good looks at their credit card statements for irregularities. "If you see small charges like $1 to $2 that could be a test charge in preparation for a big hit."

Flattery said authorities believe that some 3,600 credit card numbers collected by the skimmer had not been compromised that is, used criminally, because they remained on the card skimmers when the pair was arrested. Usually, Flattery explained, these devices just collected the numbers and then the numbers would get dumped into a computer.

While big data breaches make the headlines, small operations like this are stealing from thousands of people as they try to go about their daily business every day.

For my security and technology observations throughout the day, find me on Twitter.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-5426
Published: 2014-11-27
MatrikonOPC OPC Server for DNP3 1.2.3 and earlier allows remote attackers to cause a denial of service (unhandled exception and DNP3 process crash) via a crafted message.

CVE-2014-2037
Published: 2014-11-26
Openswan 2.6.40 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets that lack expected payloads. NOTE: this vulnerability exists because of an incomplete fix for CVE 2013-6466.

CVE-2014-6609
Published: 2014-11-26
The res_pjsip_pubsub module in Asterisk Open Source 12.x before 12.5.1 allows remote authenticated users to cause a denial of service (crash) via crafted headers in a SIP SUBSCRIBE request for an event package.

CVE-2014-6610
Published: 2014-11-26
Asterisk Open Source 11.x before 11.12.1 and 12.x before 12.5.1 and Certified Asterisk 11.6 before 11.6-cert6, when using the res_fax_spandsp module, allows remote authenticated users to cause a denial of service (crash) via an out of call message, which is not properly handled in the ReceiveFax dia...

CVE-2014-7141
Published: 2014-11-26
The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and crash) via a crafted type in an (1) ICMP or (2) ICMP6 packet.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?