Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

2/27/2017
10:25 AM
50%
50%

Two Charged In Gas Station Card-Skimming Scheme

Two individuals face federal charges for skimming debit card information from gas station pumps across multiple states.

Two people have been charged in a multi-state scheme to defraud victims and steal bank and credit union account information, reports the Department of Justice. A federal grand jury charged Eunises Llorca-Menses of Florida, and Reiner Perez-Rives of Texas, with wire fraud, conspiracy to commit wire fraud, and aggravated identity theft.

Court documents state the two employed skimming devices, which can be installed on gas pumps and record credit/debit card numbers and PINs without victims' knowledge. They allegedly rented vehicles and traveled across Florida, Alabama, Tennessee, and Virginia, visiting gas stations and installing devices along the way.

At the time of their arrest, law enforcement found the two with 39 credit/debit cards that had been re-encoded with stolen numbers, and 315 types of gift cards.

Read more details from the DoJ.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
webbrowan
50%
50%
webbrowan,
User Rank: Apprentice
3/24/2017 | 12:28:26 AM
Hi
It's scary to think about how reliant people are on their credit and cashless payment methods that identity theft can become so rampant and easy for hackers. We need to be more vigilant when we are checking our statements to ensure that we catch the lapse in security when it happens!
Valet Portland
50%
50%
Valet Portland,
User Rank: Apprentice
3/24/2017 | 1:26:57 AM
Valet
It's kind of sad because at any moment, it's going to be computer systems that will be the cause for our demise. 
Data Privacy Protections for the Most Vulnerable -- Children
Dimitri Sirota, Founder & CEO of BigID,  10/17/2019
State of SMB Insecurity by the Numbers
Ericka Chickowski, Contributing Writer,  10/17/2019
Tor Weaponized to Steal Bitcoin
Dark Reading Staff 10/18/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
2019 Online Malware and Threats
2019 Online Malware and Threats
As cyberattacks become more frequent and more sophisticated, enterprise security teams are under unprecedented pressure to respond. Is your organization ready?
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-9501
PUBLISHED: 2019-10-22
The Artificial Intelligence theme before 1.2.4 for WordPress has XSS because Genericons HTML files are unnecessarily placed under the web root.
CVE-2019-16971
PUBLISHED: 2019-10-22
In FusionPBX up to 4.5.7, the file app\messages\messages_thread.php uses an unsanitized "contact_uuid" variable coming from the URL, which is reflected on 3 occasions in HTML, leading to XSS.
CVE-2019-16972
PUBLISHED: 2019-10-22
In FusionPBX up to 4.5.7, the file app\contacts\contact_addresses.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, leading to XSS.
CVE-2019-16973
PUBLISHED: 2019-10-22
In FusionPBX up to 4.5.7, the file app\contacts\contact_edit.php uses an unsanitized "query_string" variable coming from the URL, which is reflected in HTML, leading to XSS.
CVE-2015-9496
PUBLISHED: 2019-10-22
The freshmail-newsletter plugin before 1.6 for WordPress has shortcode.php SQL Injection via the 'FM_form id=' substring.