Crooks Net Millions in Coordinated ATM Heists

FutureV

Professional
Messages
318
Reputation
36
Reaction score
53
Points
28
Organized cyber criminals stole almost $11 million in two highly coordinated ATM heists in the final days of 2012, KrebsOnSecurity has learned. The events prompted Visa to warn U.S. payment card issuers to be on high-alert for additional ATM cash-out fraud schemes in the New Year.

According to sources in the financial industry and in law enforcement, the thieves first struck on Christmas Eve 2012. Using a small number of re-loadable prepaid debit cards tied to accounts that they controlled, scammers began pulling cash out of ATMs in at least a dozen countries. Within hours, the perpetrators had stolen approximately $9 million.

Then, just prior to New Year’s Eve, the fraudsters struck again, this time attacking a card network in India and making off with slightly less than $2 million, investigators say.

The accounts that the perpetrators used to withdraw money from ATMs were tied to re-loadable prepaid debit cards, which can be replenished with additional funds once depleted. Prepaid card networks generally enforce low-dollar limits that restrict the amounts customers can withdraw from associated accounts in a 24 hour period. But in both ATM heists, sources said, the crooks were able to increase or eliminate the withdrawal limits for the prepaid accounts they controlled.

Shortly after the second heist, Visa released a private alert to payment card issuers, warning them to be on the lookout for additional ATM mega-heists over the New Years holiday. Sources say Visa’s alert was indeed prompted by the multi-million dollar heists at the end of December.

The Visa alert (PDF), sent to card issuers at the beginning of January 2013, warns:

“Visa has been alerted to new cases where ATM Cash-Out frauds have been attempted and successfully completed by organized criminal groups across the globe. In a recently reported case, criminals used a small number of cards to conduct 1000’s of ATM withdrawals in multiple countries around the world in one weekend.”

“These attacks result from hackers gaining access to issuer authorization systems and card parameter information. Once inside, the hackers manipulate daily withdrawal amount limits, card balances and other card parameters to facilitate massive fraud on individual cards. In some instances over $500K USD has been withdrawn on a single card in less than 24 hours.”


It remains unclear who the victim prepaid card issuer is, or which organization(s) may have been hacked to supply the funds added to the counterfeit prepaid cards. But as Visa notes, the fact that the attackers were able to raise or eliminate the daily withdrawal limits on the cards means they had access to the internal systems of a prepaid card network. Such access may have allowed the attackers to in effect print their own money.

This has happened in at least two other high-dollar ATM heists over the past few years. In May 2011, Jacksonville, Fla. Based Fidelity National Information Services (FIS), the nation’s largest processor of prepaid debit card payments, disclosed that it had been the victim of a similar, $13 million coordinated ATM heist scheme earlier in the year. The company indicated in a filing with the Securities and Exchange Commission a few months after the incident that the loss was the result of an intrusion at WildCard Systems Inc., a prepaid provider it had acquired in 2007. In that scheme, the thieves cloned a handful of cards tied to reloadable prepaid cards on WildCard’s network, and were able to reload the cards with funds each time they were depleted by rapid-fire ATM withdrawals.

FIS said through a spokesperson that neither it nor any of its partners had been impacted by a recent security breach.

In December 2008, RBS Worldpay disclosed that hackers had stolen $9 million in a coordinated ATM heist involving 44 counterfeit payroll debit cards that were used to withdraw funds from at least 2,100 ATMs in at least 280 cities worldwide. In that attack, the perpetrators also used re-loadable prepaid cards, and had obtained access to RBS systems that allowed them to increase the daily withdrawal limits and reload the accounts with stolen funds.

Source: http://krebsonsecurity.com/2013/02/crooks-net-millions-in-coordinated-atm-heists/ (The asshole).
 

knifewash3r

Carder
Messages
45
Reputation
5
Reaction score
6
Points
8
they got lucky RDP server with password 123 of prepaid card company's atm processor ;-)
 

dum.ps

Seller of:,  Dumps
Messages
228
Reputation
15
Reaction score
19
Points
18
knifewash3r, Most probably..
 

dezz

Member
Messages
20
Reputation
1
Reaction score
1
Points
3
does are carders.....
 

dagonxx

Professional
Messages
256
Reputation
21
Reaction score
38
Points
28
It is good question how they removed the limits, does anyone know?

I a different story the other month when some black dude got his BOA account set to unlimited by accident and he pulled out 1 million from casino ATMs. So is this only a "test" feature or is it a feature reserved for billionaire clients or what?
 

rainwater

Member
Messages
29
Reputation
3
Reaction score
3
Points
3
These attacks result from hackers gaining access to issuer authorization systems and card parameter information. Once inside, the hackers manipulate daily withdrawal amount limits, card balances and other card parameters to facilitate massive fraud on individual cards. In some instances over $500K USD has been withdrawn on a single card in less than 24 hours.”

This is one example of how it was done but there are other ways also. Here in canada I have seen the srilankan's raise the limit of any bank issued credit cards from 5000$ to 25,000$ on a single night and have the target go to casino's to pull out. They can have access to all networks so another trick is in play here.
 

Wolf_Pack

Carder
Messages
43
Reputation
1
Reaction score
3
Points
8

This is one example of how it was done but there are other ways also. Here in canada I have seen the srilankan's raise the limit of any bank issued credit cards from 5000$ to 25,000$ on a single night and have the target go to casino's to pull out. They can have access to all networks so another trick is in play here.

How did they raise the limit? Just a general idea maybe company insider
 

nev3r0ng

Professional
Messages
145
Reputation
19
Reaction score
26
Points
28
hitting 1000 atms ... in one weekend now that s what they call *gang bang*

** i can bet 90 % cashiers didnt even know they were part of sumthing so big ... as they must have been concernd with thier 5 cards :) and their 2k widrawl !!!

hats off to guys who planned it .. charged every dumb cashier 70 % of loot and made away with it :p
 
Last edited:

MikeySwipe

Member
Messages
26
Reputation
0
Reaction score
3
Points
3
Been part of this every year but this one, Every year i would cashout unlimited card when i check how much left in receipt it says 600k+ withdrawing madly, in less than one hour of cashout the card just Puff... finished.
 

Wolf_Pack

Carder
Messages
43
Reputation
1
Reaction score
3
Points
8
Been part of this every year but this one, Every year i would cashout unlimited card when i check how much left in receipt it says 600k+ withdrawing madly, in less than one hour of cashout the card just Puff... finished.

You remember the bins or how this was possible? Were they prepaid, cc+pin or bank debit cards? Which country?
 

MikeySwipe

Member
Messages
26
Reputation
0
Reaction score
3
Points
3
American bins. sometimes Visa and sometimes mastercard. Never other brands.
 
Top