Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

7/16/2013
04:48 PM
50%
50%

Hackers Hawk Stolen Health Insurance Information In Detailed Dossiers

Stolen identity "kitz" come complete with health insurance info, banking information, physical copies of credit cards, and more

The phrase "health insurance" may conjure up images of medical bills for some people, but for hackers it leads only to visions of dollar signs.

According to Dell SecureWorks, health insurance information ranging from contract numbers to the type of plan a customer has purchased is increasingly making its way into detailed dossiers of hacking victims that are being assembled and given to identity thieves in underground cyberforums. These packages of data on individual people, which also include verified bank account numbers and credentials, Social Security numbers, and other personally identifiable information, are known in the underground as "fullz."

When further packaged with custom manufactured or counterfeit physical documents, such as credit cards and driver's licenses, the hacker merchandise is referred to as "kitz," each of which sells for between $1,200 and $1,300 apiece.

"Selling fullz and kitz aren't new, but the selling of kitz, which is focused on health insurance credentials and all the other supporting credentials and documents needed to use those stolen health insurance credentials, is a new trend," says Don Jackson, senior security research for Dell SecureWorks' Counter Threat Unit. "Selling health insurance credentials by themselves does not have enough value, as those other credentials are needed to obtain medical services."

The fullz tend to go for less, about $500 each based on what is included -- full names, addresses, phone numbers, email addresses with passwords, and so on. Health insurance credentials are $20 each, with an additional $20 added whenever there is a dental, vision, or chiropractic plan associated with the health plan. Other fees include $1 to $2 for a U.S. credit card with CVV code, or $20 to $200 for a PayPal account with a verified balance.

The health insurance information, says Jackson, is being used to get free medical services. Theft of medical services, including doctor visits, drugs, and surgeries, are the primary goal for buying these stolen credentials, he says.

"We have seen the cost of health insurance and the cost of medical services continue to rise," Jackson says. "As such, we have seen more demand for stolen health insurance data and the associated credentials needed to use the health insurance, such as physical documents like the insurance card, the driver's license, the SSN, address, payment card, etc. There is definitely an increase in the buying and selling of information like health insurance contracts. So the selling of kitz with this type of information, like health insurance credentials, is on the rise, and that is a new trend."

Additionally, the cost of obtaining the stolen health insurance information and related financial and PII data has not increased, which is a big benefit for the hackers stealing the data, he adds.

The biggest jump in value among stolen credentials involved gaming accounts. Those credentials are valued from between $5 and $1,000, according to Dell SecureWorks. In recent weeks, both Konami and Nintendo revealed that attackers had compromised tens of thousands of user accounts.

"When a seller says their stolen credentials have been validated, they usually charge more for them," he says. "If, for example, the hackers' primary job is to sell stolen credit cards, then they will give the potential buyer contact info for a third party who will validate that the credit cards are good and available to use. And if the stolen data does not end up being what the seller says it is ... then there are numerous hacker forums where sellers are rated and reviewed. Most of the validation comes through the forums and what others say about the seller."

Though Jackson did not identify specifically who was behind the underground marketplaces hawking the data, he suspects the criminals involved in one major operation are located in the U.S.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message. Brian Prince is a freelance writer for a number of IT security-focused publications. Prior to becoming a freelance reporter, he worked at eWEEK for five years covering not only security, but also a variety of other subjects in the tech industry. Before that, he worked as a ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
jaysimmons
50%
50%
jaysimmons,
User Rank: Apprentice
8/1/2013 | 3:07:14 AM
re: Hackers Hawk Stolen Health Insurance Information In Detailed Dossiers
This seems like a scene that could come straight from a movie. I knew there was a huge amount of personal data being stolen daily, but the hacker underground with a full market and price ranges for specific information seems pretty surreal. It makes you realize why there is such a movement against having centralized medical records and why providers prefer to shun interoperability in favor of keeping their patient records secure.

Jay Simmons
Information Week Contributor
How Attackers Infiltrate the Supply Chain & What to Do About It
Shay Nahari, Head of Red-Team Services at CyberArk,  7/16/2019
US Mayors Commit to Just Saying No to Ransomware
Robert Lemos, Contributing Writer,  7/16/2019
The Problem with Proprietary Testing: NSS Labs vs. CrowdStrike
Brian Monkman, Executive Director at NetSecOPEN,  7/19/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-12551
PUBLISHED: 2019-07-22
In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the Memcpy function (provided by the scripting engine) allows an attacker to overwrite arbitrary memory, which could lead to code execution.
CVE-2019-12552
PUBLISHED: 2019-07-22
In SweetScape 010 Editor 9.0.1, an integer overflow during the initialization of variables could allow an attacker to cause a denial of service.
CVE-2019-3414
PUBLISHED: 2019-07-22
All versions up to V1.19.20.02 of ZTE OTCP product are impacted by XSS vulnerability. Due to XSS, when an attacker invokes the security management to obtain the resources of the specified operation code owned by a user, the malicious script code could be transmitted in the parameter. If the front en...
CVE-2019-10102
PUBLISHED: 2019-07-22
tcpdump.org tcpdump 4.9.2 is affected by: CWE-126: Buffer Over-read. The impact is: May expose Saved Frame Pointer, Return Address etc. on stack. The component is: line 234: "ND_PRINT((ndo, "%s", buf));", in function named "print_prefix", in "print-hncp.c". Th...
CVE-2019-10102
PUBLISHED: 2019-07-22
aubio 0.4.8 and earlier is affected by: null pointer. The impact is: crash. The component is: filterbank. The attack vector is: pass invalid arguments to new_aubio_filterbank. The fixed version is: after commit eda95c9c22b4f0b466ae94c4708765eaae6e709e.