April 3, 2006 7:27 PM PDT
Payment processor fears credit card crooks
- Related Stories
-
Suffering in silence with data leaks
March 29, 2006 -
Your secret PIN may not be so secret
March 16, 2006 -
Prosecutor: Debit card crime ring busted
March 13, 2006 -
Consumers, retailers grapple with data theft
June 22, 2005
Several Web hosting companies that use the
"These hackers got their hands on high quality data, and they used merchants of ours to run that data through the merchant's Web site, which goes through our platform," said David Schwartz, a spokesman for Authorize.Net in American Fork, Utah. The company says more than 130,000 merchants use its online payment service.
The Web hosting companies discovered the unusual charges through e-mail alerts that Authorize.Net sends after each transaction. Close to 3,000 suspicious transactions were pushed through the merchant accounts of three companies with which CNET News.com spoke, and more likely happened at other Web hosts, these three companies said.
Unclear, however, is where the weakness in the transaction chain is, whether it was at the level of the payment processor or the Web hosts. Also unclear is where the culprits obtained the card information they used in the transaction attempts.
On Sunday morning, in about an hour-and-a-half time period, fraudsters ran close to 1,500 transactions through the Authorize.Net account of
Lance Conway, president of
In all cases, the information that was put through the system included a card number, expiration date, name and address, representatives for the Web hosts said.
The episode is another example of
The three Web hosting companies have all voided the fraudulent transactions, which took up significant time, the company representatives said. Nevertheless, some consumers noticed that their banks had put holds on their credit cards or even charged their debit cards, and they called the Web hosting companies for clarification.
"We try to explain to them: 'No we're not thieves, we're not stealing your money, your credit card information was stolen,'" said Kiblin. His company, Defender Technologies, has fielded calls from about 100 cardholders, he added.
Conway at Viper Logic received about 30 calls over the weekend, and his phone was ringing often on Monday as well, he said. "What a nightmare. We're just a small company; there are only eight of us here."
Though the attackers already had control over a database of credit card numbers, Authorize.Net and the Web hosting companies are pointing fingers as to who is to blame for allowing the mass charges to the accounts. The Web hosts say there are no traces of transactions on their servers, so fraudsters must have accessed Authorize.Net directly.
But Authorize.Net denies any blame.
"Authorize.Net did not suffer from any sort of security breach whatsoever," Schwartz said. "If someone commits fraud in a physical store using a stolen credit card, the merchant would never hold the manufacturer of the card-swipe terminal accountable for that fraud. In the e-commerce world, a payment gateway is the equivalent."
The Web hosting companies may have left open a door to the payment processing service, possibly through their online shopping carts, Schwartz speculated.
Opinions also differ on why someone would want to send large amounts of money into the accounts of the Web hosts.
"It looks like somebody was fishing with a credit card list, trying to validate credit cards," said Kiblin. "The goal for these guys, if a card is valid, they go off and start buying stuff. All these guys that got hit are going to see other charges."
But for that to be true, the transaction amounts are too high, Schwartz said. "Usually, when hackers try to validate whether a card is good or not, they will do an authorization attempt for a dime. If it goes through, they know they have got a good card number, and when it is rejected it is going to reject whether it is a dime or $700," he said.
Avivah Litan, an analyst with Gartner, agreed. She suspects the culprits had figured out the Authorize.Net system. They may have intended the money to eventually be directed into a merchant's account outside Authorize.Net, where they could siphon it out later. But they were tripped up by the e-mail notifications Authorize.Net sends to its users.
"It was on a weekend; they always do this stuff on weekends, when no one is around watching these systems. If there were no e-mail alerts, the money would have gone into the merchant account and they would have redirected it into their account and no one would have known," Litan said. "They got caught with their pants down."
See more CNET content tagged:
Authorize.net,
debit card,
Web hosting company,
hosting company,
Web hosting

Stupid scriptbabies. Making things hard for an honest russian to make some money.
I don't click on links in emails
I delete all html emails or emails with pics and attachments and do not read them
Live behind a router firewall
Run ZoneAlarm, Norton, and Microsoft Anti Spyware
Don't give out my card information on the phone.
Pretty much try to live a nice, paranoid, secure web existence, though I do use my card online...
I'm thinking that I have a keylogger or other spyware that's infected my network that none of the sofware I mentioned can detect...
Thoughts?
TWO The expiration dates also do not matter for most cases as long as they are in the future and the card has not been canceled.
THREE even if the processor used the CVV2 code or Security code on the card ---- Most of the time, the processor does not process that code, so again, the information is not useful.
FOUR Hackers usually would not CHARGE a card for that amount of money, unless they are really stupid. They would perform an Authorization ONLY transaction, which tests if the card is valid.
FIVE If the hackers had access to the merchant accounts, THEN they would not bother with charges to any stolen or created card numbers, They would create REFUNDS to their OWN cards, usually DEBIT cards or CHECK cards.
It is the REFUNDS that are important, not the charges!
Think about it. Why in H would someone try to charge a card, when they live outside this country?
The Russian Hacker case 1999-2002 ERA, used the Merchant Accounts to REFUND money back to their own cards, not charge stolen or other cards.
I know, I helped the FBI track them down.
So, something is rotten in the above story. Either the information it totally fabricated or someone is trying to cover up the actual events.
If the report is just reporting the charges of the cards, then they MISSED the transactions which were refunds. As the charges were designed to create a smoke screen for the obvious rip-off.
So, I would check ALL the transactions and watch out for the refunded cards too, as some cards may be refunded just to cloud the issue.
Imagine that nice little old lady that just got $25,000 into her bank account just so that the data would confuse the investigators. There are far too few people that understand credit card processing and far too many holes to close.
However, what most people tend to overlook, is that as a shareholder, if you read ,digest and analyse their bottom line figures of the annual reports from all Banks, the real losses that occur in system, are not from frauds, for they are small banana's, but from very bad indiscriminate lending to every tom, dick or harriet that walks through the door! Even the annual FTC report shows that to be so as well!(look at the big Four Bank's annual declared profits and tax paid figures and compare that to FTC losses from fraud within the industry!!)
So it is the old story, to generate the ever increasing profit from a shrinking market, fees and charges increase annually, on an exponential basis to cover all losses, with too many cuts and too many corners taken, and unfortunately, end user merchant and customer security is always the last man, on the list of things to do, due to the high costs of a simple but adequate means to do so! So maybe the next generation multi core 128 bit cpu's may be an answer, and then again may be not!
Question,which is valued the highest "Profits" or "Customer Data Security"?
Ah, the age of "Customer Last", has arrived with a vengance!, for it is always the paying customer who is covering both the hidden cost of poor lending, but all frauds as well, and then paying for up to 80% of the declared profits! Also the Banks have a very large figure, to purposely reduce their tax rate, so it is essentially not in their interest, not to attack losses on frauds, just minimise it on the periphial, for the paying customer is totally covering it, in the additional fees and charges!
So not only is the Bank's paying customer covering all the losses, the general public's government tax rate is increased to compensate for the much reduced taxes received from the Banking Industry! On the retail front at the store we are also billed! A truly vicious circle on the treadmill!
Do they care about their customers, highly unlikey, for they are the sacraficial lambs, scapegoats and sheep to be fleeced, to cover any fraud permeated!, on all fronts!
That's about a half a cents worth, on this diatribe!
Choices, are very cruel in real life!