US PIN Scam Reveals Security Failings

By Peter Wakeford
Published on 3 Jul 2008
AddThis Social Bookmark Button
US PIN Scam Reveals Security Failings

Hackers are alleged to have remotely accessed customers' PIN details.

An astonishing PIN code scam has been uncovered by US authorities.
A case currently working its way through the New York court system - details of which have only recently been made public - alleges that three hackers of Russian origin were able to steal at least £1 million by using numbers entered at Citibank cash machines at the 7-Eleven convenience store chain.

While the exact methods perpetrated by the alleged fraudsters remain unclear, it is thought that they broke into the PIN system through a server at a third-party company which processed the numbers for 7-Eleven. This means that they were able to access the numbers without ever having to be physically present at a cash machine.

The case also marks a general evolution in PIN fraud, from the time in which the number could only conceivably stolen by either intercepting letters containing the number or physically looking over a bank customer's shoulder as it was entered. However, with the development of a new PIN infrastructure operated by Windows, cracks have emerged in security.

It is thought that, with the technological advances, some banks are inadvertently "leaking" the numbers by insufficiently encrypting them as they work through the system.

Commenting on the case to the Times, security analyst with Gartner research firm Avivah Litan said: "PINs were supposed be sacrosanct. What this shows is that PINs aren't always encrypted like they’re supposed to be. The banks need much better fraud detection systems and much better authentication."

Don Jackson at SecureWorks added: "What makes this case unique is the sheer luck of happening upon these guys and catching them red-handed, but there are a whole lot of other and PIN compromises going on that aren’t reported."

Citibank has yet to comment on the case.
 

Compare current accounts via money.co.uk

Money Saving Newsletter

Already registered? Login Here

Email:

We will NOT pass your details on to any third party.

See some of the recent tips you could have benefited from.

Your privacy:

Read our privacy policy.
We are registered with the Data Protection Act (1998): No. Z6245956
details
We are regulated by the Financial Services Authority: No. 415689
details



Add Your Comment

Name: 
Comment: 
You have 1000 characters left.

Latest Current Accounts Articles & News

Current Accounts Articles

ALIL Highlights Expat Current Account Concerns
ALIL Highlights Expat Current Account Concerns

New analysis from the financial firm covers current accounts for UK workers planning to live overseas.

Lloyds TSB Slammed for Handling Fees
Lloyds TSB Slammed for Handling Fees

Converting two £20s and a £10 into a £50 note costs an extra £5 - if you are not a customer at the bank.

Current Account Customer has '£100bn Overdraft' Shock
Current Account Customer has '£100bn Overdraft' Shock

Barclays later blamed the astonishing current account statement on a computer error.

UK Bank Credit Plan Gets EU Support
UK Bank Credit Plan Gets EU Support

The European Commission has welcomed the Treasury's bank plan amendments.

Poland Money Transfer System Launched by Bank
Polish Money Transfer System Launched by Bank

The service is the first to be hosted by a "donor" country for direct mobile phone money transfers.

Banks 'Could Pay Out £1bn' if Charges Case is Lost
Banks 'Could Pay Out £1bn' if Charges Case is Lost

There will be pressure on financial firms - particularly those part-nationalised by the government - to pay out quickly if they fail in the High Court case.

Careworker Offered £84 million Overdraft
Careworker Offered £84 million Overdraft

"I thought it was funny with the credit crunch," Kaylie Coomber said of the astonishing mistake.

HBOS Continues to Shrink Balance Sheet
HBOS Continues to Shrink Balance Sheet

Big HBOS PFI schemes are now held in a seperate fund, ahead of this week's vote on the £12 billion HBOS/Lloyds TSB merger.

Popular Related Articles

NS&I Forecasts Rise in Savings
NS&I Forecasts Rise in SavingsFalling inflation rates could have an impact elsewhere in the economy, the savings firm claim.

Latest Related Headlines

Rock Shareholders Await Review
Northern Rock Shareholders Await ReviewThe group wants more compensation for their holdings in the nationalised financial firm, which collapsed in 2007 due to the credit crunch.

Other Money Headlines

Government Plan to Name and Shame 'Sexist' Companies
Government Plan to Name and Shame 'Sexist' CompaniesMinisters are considering plans to force companies into publishing in-depth details of their employee's salaries, ordered by gender.
RSS FeedCurrent Accounts News
RSS FeedLatest Headlines
Free Services Money Saving Newsletter
The best money saving deals, freebies, rate alerts and advice emailed to you every week.
Enter your email:
Find Companies Related Guides RSS Feeds - Subscribe!
The "advice" given in our money saving tips is for information purposes only and should not be construed as "financial advice".
money.co.uk recommends you seek professional advice before proceeding with any investment or financial decision.
Site Map | Privacy Policy | About Us | Contact Us
money.co.uk is a trading name of Dot Zinc Limited, who are authorised and regulated by the Financial Services Authority. FSA Registration Number: 415689.
Copyright © www.money.co.uk / Dot Zinc Limited 2002-2009. All rights reserved.
Home | Login | Sign Up