Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

3/10/2011
10:35 AM
George V. Hulme
George V. Hulme
Commentary
50%
50%

Watch Where You Swipe

We tend to focus attention toward online data and identity theft and forget that we can be targeted just as easily offline.

We tend to focus attention toward online data and identity theft and forget that we can be targeted just as easily offline.A couple of years ago I noticed strange, and hefty, charges were quickly racked up on one of my credit cards. I had only used that card at one restaurant in the month prior, so I had a pretty good idea where the card account data was stolen. It wasn't a big deal getting the charges removed from my account and reopening a new one. It was a couple hours on the phone and some paperwork. Done.

Fortunately, it was much easier than what had happened fifteen years ago at a gym where I often worked out at the time. In that incident, I returned to my locker only to find the neck of the combination lock sliced with bolt cutters and on the floor. My gym bag was shuffled and my wallet gone. It wasn't long before I noticed items I hadn't bought on my statements, and I started getting collection calls from accounts I hadn't opened.

Nightmare. That incident took months to clean up and a year to get my credit report back into proper shape. Only thing fortunate was that I didn't need new credit for anything that year.

Those two incidents are why I can empathize so easily with the victims of the latest batch of credit card skimming attacks in Southern California. According to prosecutors, two men face felony charges for planting card skimming devices inside several gas pumps in Los Altos and Mountain View late last year.

From the LosAltos Patch:

Deputy District Attorney Tom Flattery said Wednesday that he received several phone calls from people who stated that they had been victims of identity theft and that they had used those gas pumps.

"If you know you've been a victim and you know you frequented one of these stations, it's logical to assume that it may have been at one of these stations," he said, adding that consumers should take really good looks at their credit card statements for irregularities. "If you see small charges like $1 to $2 that could be a test charge in preparation for a big hit."

Flattery said authorities believe that some 3,600 credit card numbers collected by the skimmer had not been compromised that is, used criminally, because they remained on the card skimmers when the pair was arrested. Usually, Flattery explained, these devices just collected the numbers and then the numbers would get dumped into a computer.

While big data breaches make the headlines, small operations like this are stealing from thousands of people as they try to go about their daily business every day.

For my security and technology observations throughout the day, find me on Twitter.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Why Cyber-Risk Is a C-Suite Issue
Marc Wilczek, Digital Strategist & CIO Advisor,  11/12/2019
DevSecOps: The Answer to the Cloud Security Skills Gap
Lamont Orange, Chief Information Security Officer at Netskope,  11/15/2019
Attackers' Costs Increasing as Businesses Focus on Security
Robert Lemos, Contributing Writer,  11/15/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-5118
PUBLISHED: 2019-11-18
A Security Bypass Vulnerability exists in TBOOT before 1.8.2 in the boot loader module when measuring commandline parameters.
CVE-2019-12422
PUBLISHED: 2019-11-18
Apache Shiro before 1.4.2, when using the default "remember me" configuration, cookies could be susceptible to a padding attack.
CVE-2012-4441
PUBLISHED: 2019-11-18
Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the CI game plugin.
CVE-2019-10764
PUBLISHED: 2019-11-18
In elliptic-php versions priot to 1.0.6, Timing attacks might be possible which can result in practical recovery of the long-term private key generated by the library under certain conditions. Leakage of a bit-length of the scalar during scalar multiplication is possible on an elliptic curve which m...
CVE-2019-19117
PUBLISHED: 2019-11-18
/usr/lib/lua/luci/controller/admin/autoupgrade.lua on PHICOMM K2(PSG1218) V22.5.9.163 devices allows remote authenticated users to execute any command via shell metacharacters in the cgi-bin/luci autoUpTime parameter.