‘Replay’ Attacks Spoof Chip Card Charges

  • 27 October 2014
  • 2 replies
  • 2 views

Userlevel 7
Badge +54
27th October 2014.
 
 
An odd new pattern of credit card fraud emanating from Brazil and targeting U.S. financial institutions could spell costly trouble for banks that are just beginning to issue customers more secure chip-based credit and debit cards.
 
http://krebsonsecurity.com/wp-content/uploads/2014/10/emvblue.png
 
Over the past week, at least three U.S. financial institutions reported receiving tens of thousands of dollars in fraudulent credit and debit card transactions coming from Brazil and hitting card accounts stolen in recent retail heists, principally cards compromised as part of the breach at Home Depot.
The most puzzling aspect of these unauthorized charges? They were all submitted through Visa and MasterCard‘s networks as chip-enabled transactions, even though the banks that issued the cards in question haven’t even yet begun sending customers chip-enabled cards.
 
Full Article

2 replies

Userlevel 7
ooops!!!! back to the drawing board for these banks to come up with a better security approach.
Userlevel 7
OOOPS,  Sounds like they made the mistake of not just having the back-end ready to go, but having it enabled too early.  They should have kept that chip-enabled portion turned off until cards had actually shipped LOL!
 
Still, the ability for the fraud to happen shows that the new secure cards, that are not even in the hands of customers, are essentially no good.  They have already been hacked.

Reply