US PIN Scam Reveals Security Failings

By Peter Wakeford
Published on 3 Jul 2008
AddThis Social Bookmark Button
US PIN Scam Reveals Security Failings

Hackers are alleged to have remotely accessed customers' PIN details.

An astonishing PIN code scam has been uncovered by US authorities.
A case currently working its way through the New York court system - details of which have only recently been made public - alleges that three hackers of Russian origin were able to steal at least £1 million by using numbers entered at Citibank cash machines at the 7-Eleven convenience store chain.

While the exact methods perpetrated by the alleged fraudsters remain unclear, it is thought that they broke into the PIN system through a server at a third-party company which processed the numbers for 7-Eleven. This means that they were able to access the numbers without ever having to be physically present at a cash machine.

The case also marks a general evolution in PIN fraud, from the time in which the number could only conceivably stolen by either intercepting letters containing the number or physically looking over a bank customer's shoulder as it was entered. However, with the development of a new PIN infrastructure operated by Windows, cracks have emerged in security.

It is thought that, with the technological advances, some banks are inadvertently "leaking" the numbers by insufficiently encrypting them as they work through the system.

Commenting on the case to the Times, security analyst with Gartner research firm Avivah Litan said: "PINs were supposed be sacrosanct. What this shows is that PINs aren't always encrypted like they’re supposed to be. The banks need much better fraud detection systems and much better authentication."

Don Jackson at SecureWorks added: "What makes this case unique is the sheer luck of happening upon these guys and catching them red-handed, but there are a whole lot of other and PIN compromises going on that aren’t reported."

Citibank has yet to comment on the case.
 

Compare current accounts via money.co.uk

Money Saving Newsletter

Already registered? Login Here

Email:

We will NOT pass your details on to any third party.

See some of the recent tips you could have benefited from.

Your privacy:

Read our privacy policy.
We are registered with the Data Protection Act (1998): No. Z6245956
details
We are regulated by the Financial Services Authority: No. 415689
details



Add Your Comment

Name: 
Comment: 
You have 1000 characters left.

Latest Current Accounts Articles & News

Current Accounts Articles

Business Overdrafts 'Frozen' by RBS
Business Overdrafts 'Frozen' by RBS

The bank will introduce the freeze on December 1st, affecting up to one million small firms.

Lloyds TSB Shareholders Back HBOS Takeover
Lloyds TSB Shareholders Back HBOS Takeover

The HBOS takeover has been given the green light by Lloyds TSB stakeholders.

Post Office May Launch Basic Current Account
Post Office May Launch Basic Current Account

Consumers may soon be able to open a current account at their local Post Office.

Bank Bailout 'Unfair on Building Societies'
Bank Bailout 'Unfair on Building Societies'

Building societies claim they are being forced to shoulder the burden of compensation paid to the savers of failed banks.

Post Office to Keep Card Account Contract
Post Office to Keep Card Account Contract

Benefits and state pension claimants will be able to carry on visiting the Post Office to receive their money.

Lloyds TSB 'Only Serious Bidder' for HBOS, Insists Brown
Lloyds TSB 'Only Serious Bidder' for HBOS, Insists Brown

The merger between Lloyds TSB and HBOS has received support from the prime minister.

HSBC Announces Writedowns
HSBC Announces Writedowns

Bad debts hit HSBC again in the three months to the end of September.

FSA Proposes Banking Sector Shake-up
FSA Proposes Banking Sector Shake-up

Current accounts and other banking services could soon by regulated by the FSA.

Popular Related Articles

Savings Providers 'Planning Rate Cuts'
Savings Providers 'Planning Rate Cuts'The Bank of England's recent interest rate reductions are being reflected by savings account providers.

Latest Related Headlines

A&L Points Out Savings Trend
Alliance & Leicester Highlight Savings TrendPeople are becoming more conservative in their spending than before, analysis from the bank has shown.
RSS FeedCurrent Accounts News
RSS FeedLatest Headlines
Free Services Money Saving Newsletter
The best money saving deals, freebies, rate alerts and advice emailed to you every week.
Enter your email:
Find Companies Current Accounts Guide RSS Feeds - Subscribe!
The "advice" given in our money saving tips is for information purposes only and should not be construed as "financial advice".
money.co.uk recommends you seek professional advice before proceeding with any investment or financial decision.
Site Map | Privacy Policy | About Us | Contact Us
money.co.uk is a trading name of Dot Zinc Limited, who are authorised and regulated by the Financial Services Authority. FSA Registration Number: 415689.
Copyright © www.money.co.uk / Dot Zinc Limited 2002-2008. All rights reserved.
Home | Login | Sign Up