ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

$3m card trick baffles hosting firms

Joris Evers CNET News.com

Published: 04 Apr 2006 09:25 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A major online payment provider said on Monday its processing service had been used in an attempt to charge money to stolen credit and debit cards.

Several Web hosting companies that use the Authorize.Net service to accept credit cards online saw a sudden spike in transactions over the weekend. The transactions, most for $500 and $700 (£300-£400), were billed to Visa, MasterCard and American Express cards that belong to people across the US, representatives for three Web hosts told CNET News.com.

"These hackers got their hands on high quality data, and they used merchants of ours to run that data through the merchant's Web site, which goes through our platform," said David Schwartz, a spokesman for Authorize.Net in American Fork, Utah. The company says more than 130,000 merchants use its online payment service.

The Web hosting companies discovered the unusual charges through email alerts that Authorize.Net sends after each transaction. Close to 3,000 suspicious transactions were pushed through the merchant accounts of three companies CNET News.com spoke to, and it is likely that more happened at other Web hosts, the three companies said.

It is unclear, however, where the weakness in the transaction chain is, whether it was at the level of the payment processor or the Web hosts. Also unclear is where the culprits obtained the card information they used in the transaction attempts.

On Sunday morning, in about an hour-and-a-half time period, fraudsters ran close to 1,500 transactions through the Authorize.Net account of Defender Technologies Group, a Web hosting firm, said Tom Kiblin, the company's chief executive. "It was just under $1m that got put through on our account," he said. Kiblin says he has reported the matter to the US Secret Service.

Lance Conway, president of Viper Logic in Palm Springs, California, and Lisa Willman, billing manager at Vortech, have similar stories. Viper's account was used on Friday to charge $700 to each of almost 800 cards, Conway said. At Vortech, that same amount was billed on Friday to about 400 cards, Willman said.

In all cases, the information that was put through the system included a card number, expiration date, name and address, representatives for the Web hosts said.

The episode is another example of credit card and debit card insecurity. Recently, a crime spree forced banks across the US to replace hundreds of thousands of debit cards. Last year a cyber break-in at a payment processor exposed names, account numbers and verification codes for 40 million credit cards.

The three Web hosting companies have all voided the fraudulent transactions, which took up significant time, the company representatives said. Nevertheless, some consumers noticed that their banks had put holds on their credit cards or even charged their debit cards, and they called the Web hosting companies for clarification.

"We try to explain to them: 'No we're not thieves, we're not stealing your money, your credit card information was stolen,'" said Kiblin. His company, Defender Technologies, has fielded calls from about 100 cardholders, he added.

Conway at Viper Logic received about 30 calls over the weekend, and his phone was ringing often on Monday as well, he said. "What a nightmare. We're just a small company; there are only eight of us here."

Though the attackers already had control over a database of credit card numbers, Authorize.Net and the Web hosting companies are pointing fingers as to who is to blame for allowing the mass charges to the accounts. The Web hosts say there are no traces of transactions on their servers, so fraudsters must have accessed Authorize.Net directly.

But Authorize.Net denies any blame.

"Authorize.Net did not suffer from any sort of security breach whatsoever," Schwartz said. "If someone commits fraud in a physical store using a stolen credit card, the merchant would never hold the manufacturer of the card-swipe terminal accountable for that fraud. In the e-commerce world, a payment gateway is the equivalent."

The Web hosting companies may have left open a door to the payment processing service, possibly through their online shopping carts, Schwartz speculated.

Opinions also differ on why someone would want to send large amounts of money into the accounts of the Web hosts.

"It looks like somebody was fishing with a credit card list, trying to validate credit cards," said Kiblin. "The goal for these guys, if a card is valid, they go off and start buying stuff. All these guys that got hit are going to see other charges."

But for that to be true, the transaction amounts are too high, Schwartz said. "Usually, when hackers try to validate whether a card is good or not, they will do an authorization attempt for a dime. If it goes through, they know they have got a good card number, and when it is rejected it is going to reject whether it is a dime or $700," he said.

Avivah Litan, an analyst with Gartner, agreed. She suspects the culprits had figured out the Authorize.Net system and intended for the money to go into the merchant account only to siphon it out later. But they were tripped up by the email notifications Authorize.Net sends to its users.

"It was on a weekend; they always do this stuff on weekends, when no one is around watching these systems. If there were no email alerts, the money would have gone into the merchant account and they would have redirected it into their account and no one would have known," Litan said. "They got caught with their pants down."

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
99 out of 159 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

Support Manager - Financial Software - London - 50/55k

My client specialises in providing payment solutions to large blue chip clients, most notably in the banking sector, they specialise in credit ...

Risk manager - Accountancy - credit risk - market risk- oil - gas

Your role would be to proactively seek the best risk returns for the business, a good understanding of trading practices and risk mitigation measures ...

Project Manager sought by Top Tier Investment Bank

This is a fantastic opportunity for a proven project manager to step up to one of the worlds leading banks and take charge of an impressive cash ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment