Rusin, whose company also sells ID protection services, likens the process of ID monitoring to having a smoke detector: “You should have a smoke detector in your house.” So the goal isn’t necessarily to stop ID fraud, but rather to manage it.
Getting to this level of access hasn’t been easy, Rusin said. Carders are tremendously paranoid. Often, just to gain access to the forums, you have to demonstrate your chops by providing up to five active credit card account numbers. It’s the equivalent of gang or mafia initiation.
While scrolling through posts in an online underground criminal forum on his laptop, Rosin explained that since “every American keeps some money in their savings account,” unlike when stealing credit cards, debit cards grant thieves immediate access to cash. Next in demand are usernames and passwords because “most people use the same password on the sites they visit.”
|
Rusin says that once a criminal has your Social Security number, it’s possible to find the rest of that personal information from various sources via Google. “Typically, they’re garnished from phishes but also from hacks. It’s everything I need to become you. So your identity in the underground is worth about 20 bucks.”
You can hear more of my interview with Tom Rusin in this week’s Security Bites podcast.
The next most common use, according to Rusin, is new-account creation. This is a slower process, and it often involves establishing utility accounts. Here, the goal is to actually become someone else so that if it ever gets to court, a jury would have a tough time determining the difference between your transactions and another’s.
In addition to having antivirus software and a firewall to protect our digital information on our desktops, it looks as if we now need ID protection for our real-world information as well.
New-account creation requires that a carder have a Social Security number, birth date, and mother’s maiden name, at least. Rusin explained that a “full” profile will contain a name, address, SSN, date of birth, and driver’s license number. Scrolling through the forum, he fingered one of the entries on the screen and said, “this guy’s selling U.S. fulls for $20.”
As CNET’s resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security. Listen to his podcast at securitybites.cnet.com or e-mail Robert with your questions and comments.
Topics: Criminal Hackers
Tags: security, Tom Rusin, Affinion, Carder, Carder forum, criminal underground, ID fraud, ID theft
Share: Digg Del.icio.us Reddit
- Facebook Twitter
Recent posts from Defense in Depth Window Snyder to leave Mozilla How to handle ID fraud’s youngest victims Is white listing going mainstream? How Live OneCare changed the antivirus landscape Express Scripts clients threatened with extortion Study: DDoS attacks threaten ISP infrastructure Security expert talks Russian gangs, botnets Extortion used in Express Scripts database breach
Related Marketers in credit card scandal start lobby effort Affinion stops buying credit-card info from e-tailers Scam probe casts harsh light on Web retail Crave giveaway of the day: official rules (1) Lenovo adds swivel and touch to its next-gen Atom Netbook RockYou sued over data breach E-tail Scrooges and how one woman defeated them Securing iPhone payment processing
Add a Comment (Log in or register) (11 Comments)
|
Unfortunately, personal information is going to flow, admits Rusin. He cites high-profile data breaches such as the ones affecting ChoicePoint and the parent company of TJ Maxx.
“Carders” are the people who buy, sell, and trade online the credit card data stolen from phishing sites or from large data breaches at retail stores. Affinion is one of the largest identity protection companies in the world, with offices in more than a dozen countries. Over the years, it has provided a wealth of information to the U.S. Secret Service and the FBI. A few weeks ago, Affinion identified .Mac users who found themselves victims of a phishing scam.
That’s an example of what’s known in the business as an “account takeover,” the most common use of personal information, in which thieves start using your active account without your knowledge. The effect is immediate, and the losses can be large.
Carders once used to peddle their wares on forums as “novs” for novelties, as though they were only providing fake accounts or fake personal details for fun. What Rusin showed me on his laptop were bold, even boastful, claims. For example, today they’re not just selling card information online.
In 2007, FaceTime Communications’ Chris Boyd and Wayne Porter gave a standing room-only talk at the RSA Conference in San Francisco on a botnet they’d traced back to the Q8 Army sites.
There is a predictable pattern. Often, the purchasing individual will first run a $1 transaction through to a charity–say, the American Red Cross. Once that transaction is authenticated, a flood of illegal purchases cascade in until the card account is shut down.
Rusin says Affinion has been establishing its carder credentials since 1998 or so. The company maintains several credit cards, accounts that they use to test their own software as well as that of others in spotting customer’s data among the carder forums. For example, they once fed an Affinion credit card account to a carder, then watched at the bank’s end of things.
Threaded among the expected offers in the forum were those for proxy servers and bullet-proof servers (i.e. servers that are unlikely to ever be shut down, located in parts of the world where the law often doesn’t reach). These are used in conjunction with phishing kits (packages that help you create your own fake Bank of America page), which are also for sale.
Terrorists, not just organized criminals, are interested in stealing and using your credit card history. That’s one of the surprising trends identified by Rusin and documented in a Department of Justice white paper (PDF) that cites the increasing involvement of terrorist networks, starting as far back as the 2002 bombing in Bali.
How 'carders' trade your stolen personal info