Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

Feds Bust $1.5 Million ATM Skimming Scheme

Romanian man failed to disguise his identity as he allegedly installed card skimmers to steal data at 40 ATMs around New York.

Federal officials Friday announced the arrest of Laurentiu Iulian Bulat, a Romanian citizen who allegedly installed card skimmers on more than 40 ATMs in the New York City metropolitan area.

Prosecutors have accused Bulat, who overstayed his U.S. visa, of participating in a fraud ring that netted at least $1.5 million via the card skimmers between May 2011 and January 5, 2012. Bulat alone was charged Thursday with conspiracy to commit bank fraud, as well as bank fraud. If convicted of both charges, he could serve up to 60 years in prison.

"ATM skimmers are high-tech bank robbers. Instead of using a gun and a note, skimmers use fake card readers and hidden cameras to steal a customer's information to get to that customer's money and take it," said Manhattan U.S. attorney Preet Bharara, in a statement. "Often it happens completely undetected."

[ There are numerous candidates, but these rate as the 6 Worst Data Breaches Of 2011. ]

According to court documents, however, Bulat was spotted after failing to disguise himself when installing card skimmers at ATM locations across Manhattan, Long Island, and Westchester, N.Y. As a result, after reviewing video footage provided by HSBC Bank, investigators had tied Bulat--dubbed "the installer" before his true identity was determined--to at least 40 ATM card-skimmer installations.

According to court documents, on January 5, 2012, "Bulat placed ATM skimming devices at two ATM machines at an HSBC Bank at 68th Street and 3rd Avenue in New York." HSBC apparently spotted him installing the skimmers on ATM video-surveillance feeds, and at 7:15 a.m. that day, contacted the Secret Service to report the apparent crime, as well as the fact that the person involved appeared to match "the installer's" appearance.

According to a statement made to the court by Secret Service special agent Eric Friedman, he went to the ATMs that morning and confirmed that skimmers had been installed on them. Then he and other agents began conducting surveillance of the ATMs. At 7:45 a.m., they saw someone matching the installer's description enter the ATM vestibule.

"He was the only person in the ATM vestibule area. (I observed him through the glass window right outside the vestibule, and had an unobstructed view)," said Friedman. "Bulat spent a few minutes at that machine, and his body was up close against the machine with his back to me. From my observation of him, he did not appear to be engaged in an ordinary ATM transaction." Friedman said Bulat then seemed to repeat the same activity at the second ATM.

Shortly afterwards, Friedman entered the ATM vestibule and arrested Bulat, who was carrying his Romanian passport, as well as a flat-head screwdriver, which Friedman told the court was often used to install or remove skimmers. Friedman said he also found a discarded gift card on the floor where Bulat had been standing, which was significant because card-skimmer installers typically test whether or not cards can easily pass through their skimmers and reach the ATM.

Card-skimming devices come in many forms, including skimmers with wireless data-transmission capabilities. But the two skimmers recovered by Secret Service agents from the HSBC ATM vestibule where Bulat was arrested employed a simpler approach: a pinhole camera, which would record customers' finger strokes as they input their PIN codes into the ATM then save the video to an internal SD card.

According to Friedman, fraud rings that install skimmers typically retrieve them within 24 to 48 hours, then process the data and tie intercepted card numbers together with PIN codes. A gang will then typically use the stolen information to make fake credit or debit cards, and then employ mules to use the cards to make purchases--frequently, high-end electronics and luxury items that can be easily resold.

The Department of Justice said that it launched an investigation in May 2011 into the fraud ring in which Bulat is alleged to have participated. That investigation remains ongoing.

InformationWeek is conducting our third annual State of Enterprise Storage survey on data management technologies and strategies. Upon completion, you will be eligible to enter a drawing to receive an Apple 32-GB iPod Touch. Take our Enterprise Storage Survey now. Survey ends Jan. 13.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Why Cyber-Risk Is a C-Suite Issue
Marc Wilczek, Digital Strategist & CIO Advisor,  11/12/2019
Unreasonable Security Best Practices vs. Good Risk Management
Jack Freund, Director, Risk Science at RiskLens,  11/13/2019
Breaches Are Inevitable, So Embrace the Chaos
Ariel Zeitlin, Chief Technology Officer & Co-Founder, Guardicore,  11/13/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2016-5285
PUBLISHED: 2019-11-15
Null pointer dereference vulnerability exists in K11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime in NSS before 3.26, which causes the TLS/SSL server using NSS to crash.
CVE-2009-5047
PUBLISHED: 2019-11-15
Jetty 6.x before 6.1.22 suffers from an escape sequence injection vulnerability from two different vectors: 1) "Cookie Dump Servlet" and 2) Http Content-Length header. 1) A POST request to the form at "/test/cookie/" with the "Age" parameter set to a string throws a &qu...
CVE-2013-4584
PUBLISHED: 2019-11-15
Perdition before 2.2 may have weak security when handling outbound connections, caused by an error in the STARTTLS IMAP and POP server. ssl_outgoing_ciphers not being applied to STARTTLS connections
CVE-2013-7087
PUBLISHED: 2019-11-15
ClamAV before 0.97.7 has WWPack corrupt heap memory
CVE-2013-7088
PUBLISHED: 2019-11-15
ClamAV before 0.97.7 has buffer overflow in the libclamav component