Connect to your account and we’ll send your message to Twitter.
Twitter Account: Not authorized (update)
Celebrating ‘The Twilight Saga: New Moon’
In honor of the opening day of New Moon, the latest film in The Twilight Saga, we thought we ...
The Cheryl Behind the Cheryl
Known to many as the long-suffering (ex)wife of funnyman Larry David, the man behind Seinfeld, ...
BlogTalkRadio Host of the Week: Alfred McComber from...
By Christina Blodgett In our continuing effort to spotlight more members of the BlogTalkRadio ...
http://IDTheftSecurity.com
Country: United States
Language: English
Follow on Twitter
Visit on Facebook
Visit on MySpace
Add to Friends
Send Message
Identity Theft Speaker, Author and Television News Correspondent Robert Siciliano is an expert on personal security and identity theft with more than 25 years of experience in security work, white collar crime prevention, and self-defense. He is a television news correspondent, security analyst, Certified Identity Theft Risk Management Specialist, CEO of IDTheftSecurity.com, and author of “The Safety Minute: Living on high alert; How to take control of your personal security and prevent fraud.”
Date / Time: 9/19/2009 3:27 AM UTC
Robert Siciliano Identity Theft Expert
Albert Gonzalez and his gang of criminal hackers, were responsible for data breaches in retailers and payment processors with some estimates saying they breached over 230 million records combined.
Gonzalez, considered a proficient criminal hacker, provided “Dumps” which is credit card data he stole from the breaches and supported the supply of “Carders”. “Carders” are the people who buy, sell, and trade online the credit card data stolen from phishing sites or from large data breaches at retail stores. Here is a video providing an example of what an online IRC forum looks like where data is bought and sold
Gonzalez who pleaded guilty to his crimes will be serving the next 15 years in jail. The techniques he and his gang used were a combination of fraud schemes that have led to a significant increase in counterfeit fraud.
Some of their tactics may have included:
Wardriving; seeking out wireless networks to crack, then installing spyware
Phishing; spoofed emails prompting the user to enter account information
Phexting or smishing; spoofed text messages prompting the user to enter account information
Key logging; using hardware or software to spy on the users PCs
ATM skimming; affixing hardware to the face of ATMs and gas pumps skimming card data
Another more advanced technique they used was called a “SQL injection”. SQL is abbreviation of Structured Query Language. Pronounced ”Ess Que El” or ”Sequel” depending on who you ask.
According to Wikipedia, a “SQL injection is a code injection technique that exploits a security vulnerability occurring in the database layer of an application.”
In other words, a SQL injection is a virus or bug that effects an application that is not properly coded or secured. There are many different configurations of various software used to build and run a website. An example would be the common Wordpress blog platform that many use and that has been found to be vulnerable. This is just one of hundreds of applications that can be hacked in this way.
IBM Internet Security Systems discovered 50% more web pages infected in the last quarter of 2008 than in the entire year of 2007.
In 2005, a now defunct 3rd party payment processor called CardSystems suffered a SQL injection, compromising a reported 40 million credit cards.
While Gonzalez has gone down, Carders are still very active. The Register reports Carder forum drops offline after hack attack. A Pakistan-based carder site has dropped off the net, after white hat hackers broke into the forum and posted details of the hack on a full disclosure mailing list.
Pakbugs.com provided a forum for ne’er do wells to discuss hacking tactics and trade malware, bank logins details and stolen credit card credentials. However this activity was interrupted after login details for the forum and email addresses were posted online following a break-in by the good guys. The white hats published a list of the Carders usernames and email addresses here.
There are:
There doesn’t seem to be a shortage of opportunity for Carders to keep up at their current pace. When a Carder hacks your credit card info that’s called “account takeover”. When they open up a new credit card account that is “new account fraud” or “application fraud”.
1. Protecting yourself from account takeover is relatively easy. Simply pay attention to your statements every month and refute unauthorized charges immediately. I check my charges online once every two weeks. If I’m traveling extensively, especially out of the country, I let the credit card company know ahead of time, so they won’t shut down my card while I’m on the road.
2. Protecting yourself from new account fraud requires more effort. You can attempt to protect your own identity, by getting yourself a credit freeze, or setting up your own fraud alerts. There are pros and cons to each.
3. Invest in Intelius Identity Protection and Prevention. Because when all else fails you’ll have someone watching your back.
Includes:
· Triple Bureau Credit monitoring – monitors changes in your credit profiles from Equifax, Experian and TransUnion-includes email alerts of any suspicious changes
· Social Security Number and Public Record Monitoring – monitors the internet and public sources for fraudulent social security number, aliases, addresses, and phone numbers
· Junk Mail Reduction – stop identity thieves from using personal information from your mailbox, trash or even phone calls by eliminating junk mail, credit card offers and telemarketing calls
· Neighborhood Watch – includes a sex offender report, list of neighbors and a neighbor report on each of your neighbors
· Identity Theft Specialists - if in the unlikely event you become a victim of identity theft our Identity Theft experts will work with you to restore your identity and good name
· Credit Report Dispute – if you find errors on your credit report we will help you resolve them quickly
· Protection Insurance and Specialists -Identity Protect has you covered with up to $25,000 in Identity Theft Recovery Insurance and access to Personal Identity Theft Resolution Specialists.
Robert Siciliano Identity Theft Speaker discussing credit card and debit card fraud on CNBC
You are not logged in. Please log in to write a comment.
LinkedIn http://www.linkedin.com/in/robertsiciliano Twitter https://twitter.com/RobertSiciliano FriendFeed http://friendfeed.com/identitytheft Blog http://realtysecurity.com/blog/ YouTube http://www.youtube.com/stungundotcom Finextra http://www.finextra.com/community/profile.aspx?id=44396 BankInnovation http://bankinnovation.net/profile/IdentityTheftSpeaker Facebook http://www.facebook.com/people/Robert-Siciliano/534933030 IMDB http://www.imdb.com/name/nm2892079/resume Wiki http://en.wikipedia.org/wiki/Robert_Siciliano
Business builder, strategic marketer, security analyst, published author, television news correspondent, actor. Deliver presentations throughout the United States and Canada on identity theft protection and personal security.
Work with Fortune 1000, IT and startups. Launching, branding, messaging, representation, m&a facilitator, SEO and media.
Current projects include dynamic biometrics, credit card platform multi-factor authentication, identity theft securityAAS, laptop tracking, security investigations and telemarketing fraud mitigation.
Specialties Appear in print, radio and televised media, on Today Show, CBS Early Show, CNN, MSNBC, FOX, CNBC, E!THSi, Inside Edition, Tyra, Montel, Maury, Howard Stern, USA Today, Forbes, Cosmo, Good Housekeeping, Readers Digest, Consumer Digest, Smart Money, NY Times, NY Post, BOS Globe, LA Times, Wash Times, Wash Post, Chicago Trib, Atl Journal, MIA Herald, SF Chronicle, SEA Times, ABC News.com, Maxim, CNet, CSO, TechRepublic, Search Security, Security Mgmt, AP, UPI, Reuters, and Entrepreneur.