CNP, Malware & Physical Attacks; The Future of Fraud in an EMV World
How Will EMV Affect Fraud In the U.S.?
Fraud After EMV Continued Skimming of Chip card for mag stripe data Chip Card will still contain Mag stripe data for foreseeable future Non Chip Location Cash-outs & International Cash-outs of stolen Mag Stripe Data Mag stripe data will have to be used at non chip location ATM Shimming Device Designed to Capture Chip Data and then is converted to mag stripe data The GOOD NEWS: Eventual & Significant Decrease in card present fraud (5+yrs)
The EMV “Ripple Effect” on Fraud Significant Increases in Card Not Present Fraud Online & telephonic purchases No more pictures of our suspects!! Significant Increases in ID Theft to Conduct Account Takeover Fraud Network Intrusions to obtain PII and password information Increase in Physical Attacks on ATMs Card Trapping / Cash Trapping / Gas Attacks & Malware Attacks Revert to Traditional Financial Institutional Fraud Counterfeit checks/Account Takeover/Wire Fraud/Cracking Cards/Loan Fraud/Synthetic ID Fraud
Card Crackin’ / Crackin’ Cards Got it’s name from Chicago area. Activity Started by “Gangster Disciples” Also known as “Drops” or “Doing Drops” or “Dropping Paper”. Organization recruits younger individuals and college aged students with good banking credit new debit accounts at financial institutions. Accountholder turns over debit card and PIN number to member of organization. Other individuals deposit counterfeit/stolen checks into the account via the ATM.
Instagram Video of Davey Hines
Adina Been CashinOut (CT Investigation)
How Much as EMV Affected Skimming (ATM Attack Statistics - EAST) ATM Skimming makes up 36% of all ATM Fraud but accounts for 90% of all ATM fraud loss. Card Trapping – 3.2 Million in losses Logical (Malware) attacks – 11.7 Million in losses Gas Attacks – 21 Million in losses Skimming – 2.4 Billion in losses
State of ATM Attacks Current (U.S.) 1 st Generation Skimmers (Digital Skimming) 2 nd Generation Skimming (Analogue) Cash Forking/Trapping Shoulder Surfing/Chaining Attacks POS Skimming Current (Europe) 2 nd Generation (Analogue Skimming 3 rd Generation (Stereo Skimming) Virtual Skimming Malware Attacks Cash Forking/Trapping Gas Attacks EMV Pos Skimming ATM Shimming
Current U.S. Trends in Skimming
Card Reader Tapping/Eavesdropping
Insert (Throat) Skimmers Photos provided by NCR
Deep Insert Skimmers Captures Mag-Stripe No Storage on Device – wireless Transmitter
Deployment of POS Skimming Evolving Fraud Trends In the U.S.
Walmart Skimmers
Ingenico i3070 tampered and legitimate device EMV POS Skimming (For Mag Stripe Data) | 57
Compromised Chip Terminal
Inserted Shimming Device
ATM Cash/Card Trapping/Forking
Malware Attacks on ATMs Malware takes control of the ATM PC to: Control communication between PC and cash dispenser. Or captured stored card data contained on drive of ATM PC
Jackpotting
Malware Circuit Board Injection Attack Macau (Chinese Territory) Malware Injection into ATM to capture/store card data and PIN
Criminals will not surrender….They will just adapt to the circumstances!
Detective Mark Solomon Greenwich Police Department CT Financial Crimes Task Force ATM Skimming Intelligence Network Coordinator IAFCI CT Chapter President (203) (cell) Questions?????