Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

How Do You Steal 130 Million Credit Card Numbers?

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Topic Forums » Economy Donate to DU
 
steven johnson Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-18-09 10:14 AM
Original message
How Do You Steal 130 Million Credit Card Numbers?
Unjustified optimism and ignorance of hacker vulnerabilities in one's data systems led to the largest data mining in history.



The historic theft involved five corporate data hackings, between 2006 and 2008, including Heartland, Hannaford, 7-Eleven and two unnamed companies, according to Channel Web. US investigators say the team scanned lists of Fortune 500 companies and learned about their checkout counter machines (also known as point-of-sale systems). Then they would write specific codes to corrupt their data systems and launch a virus from computers in the United States and Europe to pull hundreds and thousands of credit card numbers, and sort through them using a "sniffer," which is basically a data analysis system that decodes big chunks of information.


How Do You Steal 130 Million Credit Card Numbers?



PC World:
Here are three tips to help you protect your data and make sure you don't become the next Heartland Payment Systems.
 
1. Wireless security. Wireless networks exist in most businesses these days. The thing about wireless networks is that they let employees roam about and still stay connected to the network, but they also provide an opportunity for unauthorized users who are within range of the wireless access point to gain access as well. The data breaches at TJX and Lowes were both made possible through weak or non-existent wireless network security.
 
Wireless networks should be segregated from the primary network to provide an extra layer of protection. The wireless connection should be secured with WPA or WPA2 encryption at a minimum. It is even better if some other form of authentication is used to access the wireless network.

2. Compliance. Payment Card Industry Data Security Standards (PCI DSS) requirements.

3. Diligence. ... you have to monitor intrusion detection and prevention system activity, firewall logs, and other data to stay alert for signs of compromise or suspicious activity.

How to Prevent a Heartland-Style Data Breach
Printer Friendly | Permalink |  | Top
Trajan Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-18-09 10:16 AM
Response to Original message
1. I received a new card from my bank ....
with a new number ....

The note mentioned a compromise by a third party of my old card .....

Hmmmmmmm ....
Printer Friendly | Permalink |  | Top
 
juno jones Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-18-09 01:52 PM
Response to Reply #1
2. Dealt with one of those myself about 2 months ago.
I wonder if this is the guy who did it.


The damn CU STILL can't get my pin to work properly.
Printer Friendly | Permalink |  | Top
 
DemReadingDU Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Aug-19-09 02:21 PM
Response to Reply #2
3. new card too, couple months ago. hmmm
Printer Friendly | Permalink |  | Top
 
jtrockville Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Aug-19-09 03:12 PM
Response to Reply #3
4. Make that 4 of us...
Bills for Acai diet pills (among other things) started showing up on my account. Fortunately my credit union noticed and called me long before I would have noticed.

ODDLY, I did receive the Acai diet pills. :shrug:
Printer Friendly | Permalink |  | Top
 
girl gone mad Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Aug-19-09 05:47 PM
Response to Reply #4
5. crap..
I got some of those in the mail and was wondering what the deal was.

Guess I'll have to go through all of my cc and debit charges line by line.
Printer Friendly | Permalink |  | Top
 
girl gone mad Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Aug-19-09 06:17 PM
Response to Reply #4
6. well, you were right..
looks like my number was stolen, too. There are a lot of small charges and charges for "health services". Headache.
Printer Friendly | Permalink |  | Top
 
jtrockville Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Aug-19-09 10:25 PM
Response to Reply #6
7. Be careful - after the small charges cleared, big ones came next.
Fortunately I was in already in the process of cancelling the card and getting a new one. I disputed all the charges (even the small ones). I had to fill out the forms and have them notarized, but it wasn't too big a pain.

Good luck to 'ya.
Printer Friendly | Permalink |  | Top
 
fasttense Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Aug-20-09 08:34 AM
Response to Original message
8. AOL let out my CC number a while back.
The charges were small and we got them removed. I got new cards and we watch our statements like hawks now.
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Sat Apr 20th 2024, 06:25 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Topic Forums » Economy Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC