Comments on: Payment processor fears credit card crooks
Authorize.Net says its service was used in an attempt to charge money to stolen credit and debit cards.
Authorize.Net says its service was used in an attempt to charge money to stolen credit and debit cards.
December 4, 2009 6:13 PM PST
December 4, 2009 4:56 PM PST
December 4, 2009 4:25 PM PST
Add headlines from CNET News to your homepage or feedreader.
More feeds available in our RSS feed index.
Related quotes
Also... the Gartner "analyst" is 100% wrong regarding using the Authorize.net system to go into the merchant's accounts and redirect it. Authnet is the middle man here. They're simply the gateway that takes the money and passes it to the Merchant's merchant account provider.
There is in fact nowhere online for you to change where funds that are supposed to go into the merchant's account online. Authnet does not even have this info as they don't make deposits into your account. The merchant provider the indiviudal business uses makes the deposit.
When I setup my online merchant account, anytime I wanted to make a change to where my funds were deposited to, I had to send them a voided check and a written authorization to make any kind of change to where funds were deposited. You can't do that kind of thing online.
To say the person who did this thing was just trying to divert money is absolutely foolish. Anyone who has ANYTHING to do with merchant accounts should know that's not possible.
Stupid scriptbabies. Making things hard for an honest russian to make some money.
>from the merchant account is 100% false. It
>doesn't work that way. Do you guys do any research
>at all before publishing a story?
The article does not mention anything about fraudsters redirecting monet from merchant accounts to themselves.
It simply mentions transactions apparently emanating from at least 3 merchants to a large number of carholders.
I don't click on links in emails
I delete all html emails or emails with pics and attachments and do not read them
Live behind a router firewall
Run ZoneAlarm, Norton, and Microsoft Anti Spyware
Don't give out my card information on the phone.
Pretty much try to live a nice, paranoid, secure web existence, though I do use my card online...
I'm thinking that I have a keylogger or other spyware that's infected my network that none of the sofware I mentioned can detect...
Thoughts?
TWO The expiration dates also do not matter for most cases as long as they are in the future and the card has not been canceled.
THREE even if the processor used the CVV2 code or Security code on the card ---- Most of the time, the processor does not process that code, so again, the information is not useful.
FOUR Hackers usually would not CHARGE a card for that amount of money, unless they are really stupid. They would perform an Authorization ONLY transaction, which tests if the card is valid.
FIVE If the hackers had access to the merchant accounts, THEN they would not bother with charges to any stolen or created card numbers, They would create REFUNDS to their OWN cards, usually DEBIT cards or CHECK cards.
It is the REFUNDS that are important, not the charges!
Think about it. Why in H would someone try to charge a card, when they live outside this country?
The Russian Hacker case 1999-2002 ERA, used the Merchant Accounts to REFUND money back to their own cards, not charge stolen or other cards.
I know, I helped the FBI track them down.
So, something is rotten in the above story. Either the information it totally fabricated or someone is trying to cover up the actual events.
If the report is just reporting the charges of the cards, then they MISSED the transactions which were refunds. As the charges were designed to create a smoke screen for the obvious rip-off.
So, I would check ALL the transactions and watch out for the refunded cards too, as some cards may be refunded just to cloud the issue.
Imagine that nice little old lady that just got $25,000 into her bank account just so that the data would confuse the investigators. There are far too few people that understand credit card processing and far too many holes to close.
>take ANY ADDRESS
This would depend on the card issuing bank's own systems. Some would verify full address with a percentage/phonetic match system. Remember that credit cards are a worldwide "system" with different issuing bank processing rules in different countries.
Expiration date matters significantly. It is part of the credit card number checksum calculation. The year matters less as long as it matches the even/oddness of the year on the real card.
In terms of the goal of this transactions, there could be many. It could simply be hackers wishing to prove that authorize.net has been compromised and possibly run them out of business.
You need to reread the second paragraph of the article.
[merchant]---[web hosting]---[http://authorize.net|http://authorize.net]---[visa/mastercard]----[merchant_s bank]---[merchant]
The article mentions the web hosting company noticing the suspicious transactions. But it also mentions an apparently honest merchant saying that the crooks used their account to charge money to a lot of cards.
So there are 2 crimes here:
1-stealing cardholder information and using this to run fraudulent transactions
2-stealing merchant account information so that the criminals could run those transactions through.
For (2), logs of authorize.net *should* show what IPs were used to generate those transactions.
Why do this ? On the surface, it appears stupid, but it may in fact be VERY smart.
Say you have 2 merchants who collude with you. You zap transactions on a 998 merchants with $700 transactions. And you put transactions worth 1398.76 and $678.27 on those 2 merchants with whom you are working. Those transactions won't appear to be lumped into the larger hacking attemps, and those those colluding merchants will get their money and split it with the fraudsters.
In other words, by hacking a large number of merchants, you can easyly slip "real" transactions under the carpet and avoid detection.
However, of the criminals were able to obtain merchant account information to be able to submit transactions to authorize.net, it means that authorize.net has a security flaw in their system.
Another possibility: disgruntled ex employee of authorze.net who had warned them of security weaknesses. he gets revenge by doing this act which will destroy authorize.net's reputation since from that article,. it is clear that merchant account information, something which authorize.net should hold confidential between merchant and itself, has been compromised
Where they got the credit card numbers/info is another issue, but it may not necessarily be from authorize.net.
- Oh well!
- by heystoopid April 8, 2006 3:30 PM PDT
- Oh well, pay peanuts!, get cheap crap security, it is a simple as that!
- Like this Reply to this comment
-
(13 Comments)However, what most people tend to overlook, is that as a shareholder, if you read ,digest and analyse their bottom line figures of the annual reports from all Banks, the real losses that occur in system, are not from frauds, for they are small banana's, but from very bad indiscriminate lending to every tom, dick or harriet that walks through the door! Even the annual FTC report shows that to be so as well!(look at the big Four Bank's annual declared profits and tax paid figures and compare that to FTC losses from fraud within the industry!!)
So it is the old story, to generate the ever increasing profit from a shrinking market, fees and charges increase annually, on an exponential basis to cover all losses, with too many cuts and too many corners taken, and unfortunately, end user merchant and customer security is always the last man, on the list of things to do, due to the high costs of a simple but adequate means to do so! So maybe the next generation multi core 128 bit cpu's may be an answer, and then again may be not!
Question,which is valued the highest "Profits" or "Customer Data Security"?
Ah, the age of "Customer Last", has arrived with a vengance!, for it is always the paying customer who is covering both the hidden cost of poor lending, but all frauds as well, and then paying for up to 80% of the declared profits! Also the Banks have a very large figure, to purposely reduce their tax rate, so it is essentially not in their interest, not to attack losses on frauds, just minimise it on the periphial, for the paying customer is totally covering it, in the additional fees and charges!
So not only is the Bank's paying customer covering all the losses, the general public's government tax rate is increased to compensate for the much reduced taxes received from the Banking Industry! On the retail front at the store we are also billed! A truly vicious circle on the treadmill!
Do they care about their customers, highly unlikey, for they are the sacraficial lambs, scapegoats and sheep to be fleeced, to cover any fraud permeated!, on all fronts!
That's about a half a cents worth, on this diatribe!
Choices, are very cruel in real life!