Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint

8/24/2009
04:45 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Hacker Ring Tied To Major Breaches Just Tip Of The Iceberg

TJX-Heartland attacker and cohorts also reportedly hacked ATM machines in 7-Elevens, but their wide net is likely just one of many

The long arm of the cybercrime gang allegedly behind some of the biggest data breaches -- TJX, Heartland Payment Systems, Hannaford Bros., and 7-Eleven -- may be connected with yet another major hack: that of a network of Citibank-branded ATM machines.

According to a new report in the Financial Times, indicted hacker Albert Gonzalez and his associates breached the ATM network of 2,200 kiosks located inside 7-Eleven stores for several months, starting in late 2007 and through around February 2008, according to law enforcement sources who spoke to FT. The ATM machines were owned by CardTronics, and the perpetrators stole card and PIN numbers from the machines to create new cards that they then used to steal about $2 million in cash from ATM machines in other locations.

The FT report says the attackers also compromised iWire cards, which were used to withdraw $5 million -- most of which was then sent to Russia.

Gonzalez, who previously had been charged for his alleged role in the breach of TJX, BJ's Wholesale Club, Barnes & Noble, and Dave & Buster's, last week was indicted for allegedly conspiring to break into computers and stealing debit and credit cards from Heartland, Hannaford's, 7-Eleven, and two other major national retailers whose names were withheld in the filing. Aside from the news that one man is suspected to have had a hand in all of these major breaches, security experts say the even bigger news is that Gonzalez and his cohorts used attack methods that are typically found in most cybercrime cases and could have been prevented with the appropriate defenses -- SQL injection, packet sniffing, and backdoor malware -- designed to evade detection.

The SQL injection attacks ultimately led to the theft of more than 130 million debit and credit card accounts.

But security experts say while the latest revelation that the gang was also allegedly hacking ATM machines shows how entrenched this group was in their online fraud, there are likely other big breaches executed by other hacker groups yet to be revealed.

"I suspect that in the future there will be larger cases than the Gonzalez scam. I think Gonzalez is really the tip of the iceberg," says Randy Abrams, director of technical education for Eset. "This isn't the only criminal gang that has long arms. The ante for entering this arena is pretty low, but the skills required to pull it off without getting caught quickly separate the pros from the script kiddies. Undoubtedly, there are more professional gangs than the Gonzalez gang."

And even more telling may be the names that weren't named in Gonzalez's indictment -- called "Hacker 1" and "Hacker 2" from in or near Russia. Security experts say Gonzalez was caught because he was in the U.S. His Eastern European accomplices aren't likely to be arrested in that region, and it's still unclear how their activities tie into other Eastern European cybercrime rings.

"He got caught up in something bigger than him, and he's taking the heat," says Paul Ferguson, a senior threat researcher at Trend Micro. "He had already been caught for previous breaches, so he's no Einstein. Something smells [fishy]."

Ferguson says while it's difficult to trace these crimes back cleanly to all of the perpetrators behind them, large breaches like those that Gonzalez allegedly helped mastermind likely come from a smaller pool of bad guys. "It's probably a much smaller group with the background and experience to perpetrate these," he says.

Day-to-day social engineering and malware campaigns, meanwhile, tend to be conducted by multiple parties and layers of cybercriminals, he says. "These tend to have a lot of people's fingers involved," Ferguson says.

The ATM breach at the 7-Eleven stores apparently began with a back-end system outsourced by 7-Eleven, according to the FT article.

While the Gonzalez case finally puts a face to some major identity theft and cybercrime incidents, many other cases are likely to come to light, some experts say.

Just because Gonzalez's alleged capers have been exposed doesn't mean he and his gang were the most prolific. "Although the Gonzalez gang has been tied to the largest known heists, it doesn't mean they are the most prolific," Abrams says. "Were it not for disclosure legislation, it is unlikely we would even know of the Heartland breach and other breaches."

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message. Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Why Cyber-Risk Is a C-Suite Issue
Marc Wilczek, Digital Strategist & CIO Advisor,  11/12/2019
The Cold Truth about Cyber Insurance
Chris Kennedy, CISO & VP Customer Success, AttackIQ,  11/7/2019
Black Hat Q&A: Hacking a '90s Sports Car
Black Hat Staff, ,  11/7/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-5230
PUBLISHED: 2019-11-13
P20 Pro, P20, Mate RS smartphones with versions earlier than Charlotte-AL00A 9.1.0.321(C00E320R1P1T8), versions earlier than Emily-AL00A 9.1.0.321(C00E320R1P1T8), versions earlier than NEO-AL00D NEO-AL00 9.1.0.321(C786E320R1P1T8) have an improper validation vulnerability. The system does not perform...
CVE-2019-5231
PUBLISHED: 2019-11-13
P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.186(C00E180R2P1) have an improper authorization vulnerability. The software incorrectly performs an authorization check when a user attempts to perform certain action. Successful exploit could allow the attacker to update a crafted package.
CVE-2019-5233
PUBLISHED: 2019-11-13
Huawei smartphones with versions earlier than Taurus-AL00B 10.0.0.41(SP2C00E41R3P2) have an improper authentication vulnerability. Successful exploitation may cause the attacker to access specific components.
CVE-2019-5246
PUBLISHED: 2019-11-13
Smartphones with software of ELLE-AL00B 9.1.0.109(C00E106R1P21), 9.1.0.113(C00E110R1P21), 9.1.0.125(C00E120R1P21), 9.1.0.135(C00E130R1P21), 9.1.0.153(C00E150R1P21), 9.1.0.155(C00E150R1P21), 9.1.0.162(C00E160R2P1) have an insufficient verification vulnerability. The system does not verify certain par...
CVE-2010-4177
PUBLISHED: 2019-11-12
mysql-gui-tools (mysql-query-browser and mysql-admin) before 5.0r14+openSUSE-2.3 exposes the password of a user connected to the MySQL server in clear text form via the list of running processes.