ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Shell's £1m chip and PIN fraud 'an inside job'

Will Sturgeon silicon.com

Published: 09 May 2006 16:10 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A £1m chip and PIN fraud at a Shell petrol station was "an inside job", according to UK payments body Apacs.

Shell suspended the use of chip and PIN payments at 600 UK petrol stations over the weekend as a precautionary measure following the theft of more than £1m from customer accounts.

A spokeswoman for Shell confirmed to ZDNet UK sister site Silicon.com that "a small number of customers have been affected" and added that the company is now co-operating with a police investigation that has already resulted in nine arrests in connection with the crime.

Shell said the company is working with the manufacturers of the chip and PIN terminals, but does not know when its petrol stations will be able to start taking chip and PIN payments again.

The spokeswoman said it is not known whether all affected customers have been informed yet but banks have issued advice to customers to check their bank accounts and statements carefully for discrepancies.

Due to the ongoing nature of the investigation, Shell declined to comment further on the specifics of the case.

But a spokeswoman from Apacs said criminals must have had easy access to PIN pads in order to modify them to enable the theft of PIN numbers and the copying of magnetic strip information — a task which will have taken time.

She said that "without any doubt" it must have been an inside job involving a "conspiring" or "coerced" member of staff.

At the heart of the problem are PIN pads which are designed to shut down if they tampered with. In the case of those supplied to Shell this didn't happen, and it appears this is the vulnerability the theives exploited, said Apacs.

It's likely the news will throw into question the reliability of chip and PIN payments, which became a requirement for most point of sale card payments in the UK in February.

However, the Apacs spokeswoman said: "In the past, one of the fraud hotspots has been petrol stations. As such it's no surprise we've got a situation like this on the forecourt.

"We've never said the fraudsters will disappear. They are organised criminals and they are very sophisticated. But cards are a lot safer now than they were two years ago."

She claimed the speed at which police have been able to make arrests owes a lot to the fact chip and PIN payments can quickly be traced back to the PIN pad which was used.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
61 out of 161 people found this useful



Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Reporting Analyst - London - 35,000 - 38,000 - Plus Benefits

You will also be required to manage the development and implementation of new reports, liaise with internal data providers, identify areas requiring ...

Support Analyst

Account management creation, administration and disabling of user accounts for trial and live purposes. Furthermore, we are a profitable company ...

Cognos EP Analyst - Insurance - London City - 45k

Ideally you would have experience in a Systems Accounts environment able to liase with financial account holders at their level. Salaries will begin ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment