Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

Feds Bust $1.5 Million ATM Skimming Scheme

Romanian man failed to disguise his identity as he allegedly installed card skimmers to steal data at 40 ATMs around New York.

Federal officials Friday announced the arrest of Laurentiu Iulian Bulat, a Romanian citizen who allegedly installed card skimmers on more than 40 ATMs in the New York City metropolitan area.

Prosecutors have accused Bulat, who overstayed his U.S. visa, of participating in a fraud ring that netted at least $1.5 million via the card skimmers between May 2011 and January 5, 2012. Bulat alone was charged Thursday with conspiracy to commit bank fraud, as well as bank fraud. If convicted of both charges, he could serve up to 60 years in prison.

"ATM skimmers are high-tech bank robbers. Instead of using a gun and a note, skimmers use fake card readers and hidden cameras to steal a customer's information to get to that customer's money and take it," said Manhattan U.S. attorney Preet Bharara, in a statement. "Often it happens completely undetected."

[ There are numerous candidates, but these rate as the 6 Worst Data Breaches Of 2011. ]

According to court documents, however, Bulat was spotted after failing to disguise himself when installing card skimmers at ATM locations across Manhattan, Long Island, and Westchester, N.Y. As a result, after reviewing video footage provided by HSBC Bank, investigators had tied Bulat--dubbed "the installer" before his true identity was determined--to at least 40 ATM card-skimmer installations.

According to court documents, on January 5, 2012, "Bulat placed ATM skimming devices at two ATM machines at an HSBC Bank at 68th Street and 3rd Avenue in New York." HSBC apparently spotted him installing the skimmers on ATM video-surveillance feeds, and at 7:15 a.m. that day, contacted the Secret Service to report the apparent crime, as well as the fact that the person involved appeared to match "the installer's" appearance.

According to a statement made to the court by Secret Service special agent Eric Friedman, he went to the ATMs that morning and confirmed that skimmers had been installed on them. Then he and other agents began conducting surveillance of the ATMs. At 7:45 a.m., they saw someone matching the installer's description enter the ATM vestibule.

"He was the only person in the ATM vestibule area. (I observed him through the glass window right outside the vestibule, and had an unobstructed view)," said Friedman. "Bulat spent a few minutes at that machine, and his body was up close against the machine with his back to me. From my observation of him, he did not appear to be engaged in an ordinary ATM transaction." Friedman said Bulat then seemed to repeat the same activity at the second ATM.

Shortly afterwards, Friedman entered the ATM vestibule and arrested Bulat, who was carrying his Romanian passport, as well as a flat-head screwdriver, which Friedman told the court was often used to install or remove skimmers. Friedman said he also found a discarded gift card on the floor where Bulat had been standing, which was significant because card-skimmer installers typically test whether or not cards can easily pass through their skimmers and reach the ATM.

Card-skimming devices come in many forms, including skimmers with wireless data-transmission capabilities. But the two skimmers recovered by Secret Service agents from the HSBC ATM vestibule where Bulat was arrested employed a simpler approach: a pinhole camera, which would record customers' finger strokes as they input their PIN codes into the ATM then save the video to an internal SD card.

According to Friedman, fraud rings that install skimmers typically retrieve them within 24 to 48 hours, then process the data and tie intercepted card numbers together with PIN codes. A gang will then typically use the stolen information to make fake credit or debit cards, and then employ mules to use the cards to make purchases--frequently, high-end electronics and luxury items that can be easily resold.

The Department of Justice said that it launched an investigation in May 2011 into the fraud ring in which Bulat is alleged to have participated. That investigation remains ongoing.

InformationWeek is conducting our third annual State of Enterprise Storage survey on data management technologies and strategies. Upon completion, you will be eligible to enter a drawing to receive an Apple 32-GB iPod Touch. Take our Enterprise Storage Survey now. Survey ends Jan. 13.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 6/5/2020
How AI and Automation Can Help Bridge the Cybersecurity Talent Gap
Peter Barker, Chief Product Officer at ForgeRock,  6/1/2020
Cybersecurity Spending Hits 'Temporary Pause' Amid Pandemic
Kelly Jackson Higgins, Executive Editor at Dark Reading,  6/2/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: What? IT said I needed virus protection!
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-13864
PUBLISHED: 2020-06-05
The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from a stored XSS vulnerability. An author user can create posts that result in a stored XSS by using a crafted payload in custom links.
CVE-2020-13865
PUBLISHED: 2020-06-05
The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from multiple stored XSS vulnerabilities. An author user can create posts that result in stored XSS vulnerabilities, by using a crafted link in the custom URL or by applying custom attributes.
CVE-2020-11696
PUBLISHED: 2020-06-05
In Combodo iTop a menu shortcut name can be exploited with a stored XSS payload. This is fixed in all iTop packages (community, essential, professional) in version 2.7.0 and iTop essential and iTop professional in version 2.6.4.
CVE-2020-11697
PUBLISHED: 2020-06-05
In Combodo iTop, dashboard ids can be exploited with a reflective XSS payload. This is fixed in all iTop packages (community, essential, professional) for version 2.7.0 and in iTop essential and iTop professional packages for version 2.6.4.
CVE-2020-13646
PUBLISHED: 2020-06-05
In the cheetah free wifi 5.1 driver file liebaonat.sys, local users are allowed to cause a denial of service (BSOD) or other unknown impact due to failure to verify the value of a specific IOCTL.