From Deseret News archives:
Computer insecurity: Citibank ATM scam shows that PINs are vulnerable to hackers
The scam netted the alleged identity thieves millions of dollars. But more importantly for consumers, it indicates criminals were able to access PINs the numeric passwords that theoretically are among the most closely guarded elements of banking transactions by attacking the back-end computers responsible for approving the cash withdrawals.
The case against three people in U.S. District Court for the Southern District of New York highlights a significant problem.
Hackers are targeting the ATM system's infrastructure, which is increasingly built on Microsoft Corp.'s Windows operating system and allows machines to be remotely diagnosed and repaired over the Internet. And despite industry standards that call for protecting PINs with strong encryption which means encoding them to cloak them to outsiders some ATM operators apparently aren't properly doing that. The PINs seem to be leaking while in transit between the automated teller machines and the computers that process the transactions.
It's unclear how many Citibank customers were affected by the breach, which extended at least from October 2007 to March of this year. The bank has nearly 5,700 Citibank-branded ATMs inside 7-Eleven Inc. stores throughout the United States, but it doesn't own or operate any of them.
That responsibility falls on two companies: Houston-based Cardtronics Inc., which owns all the machines but only operates some, and Fiserv Inc., based in Brookfield, Wis., which operates the others.
A critical issue in the investigation is how the hackers infiltrated the system, a question that still hasn't been answered publicly.
All that's known is they broke into the ATM network through a server at a third-party processor, which means they probably didn't have to touch the ATMs at all to pull off the heist.
Comments
A Citibank ATM machine is available to customers at a 7-Eleven in Palo Alto, Calif. A security breach in Citibank ATMs at 7-Eleven stores has led to millions of dollars in fraudulent cash withdrawals from hijacked accounts and a criminal indictment that points to an international crime ring. Especially troubling is that the ring apparently found a new way to grab PINs, the most sensitive part of a consumer's banking record. The hackers infiltrated the ATM network through a server at a third-party processor, which means they probably didn't have to touch the ATMs at all to pull off the heist.
- Letters: Good nutrition is key 12:11 a.m.
- Letters: Bennett should retire 12:11 a.m.
- Letters: Lawyers want to win 12:11 a.m.
- Letters: Budget methods bizarre 12:11 a.m.
- Letters: Rethink rehiring rules 12:11 a.m.
- Letters: Need just cause 12:11 a.m.
- Letters: Torture unacceptable 12:11 a.m.
- Wednesday on TV 12:04 a.m.
- Mormon Olympian rides on her faith 12:04 a.m.
- Birthdays for Feb. 10 12:04 a.m.
- High school players commit to BYU
- Utah Jazz Ironmen
- 15-month-old Rachel Toone dies
- LDS veggie program helps Bolivians
- Teacher merit pay debated
- SLC's City Creek moves ahead
- Utahn's 'Caveman Diet' catching on
- MWC race shaping 'Survivor' style
- 'Faces of America' recommends LDS
- Kaman, not Boozer, on All-Star team
- Teacher merit pay debated
194 - UNLV bombs BYU into loss
186 - Countering attacks on LDS scholarship
163 - White House mocks Sarah Palin
101 - High school players commit to BYU
91 - Rally in opposition to benefit cuts
90 - Let's talk college hoops
78 - BYU's prime postseason position?
77 - Possible Constitution draft found
72 - Who Dat! Saints beat Colts
71
To the 6:30 commentor, Considering the violence that has been directed...
Our prayers are with you. They are such beautiful girls. This makes me sad...
These cuts are on top of the fiscal year 2010 cuts. The impact isn't just 2.5%.
Yes. Anybody over 15 should not be allowed to comment. This movie was...
Any legislator that denies global warming at this stage doesn't deserve...
What straws are you talking about? Pretty solid science. I say bogus on you.
You are assuming pioneers had a higher quality of life than ancient hunter...
I was led to think the higher you sit the further you see. Tonight I could...
So terribly, terribly sad. Sincere condolences to this unfortunate family.
My absolute favorite - the Hot Chocolate-Hot Carmel Sundae!!! My oldest...



You can be the first to comment on this story.