Millions of Citibank Customers at Risk Due to Largest PIN Number Hacking in History   - 2,160 Views,

Summary: A breaking news report (why is it breaking in England, not here in the U.S.?) reveals that millions of Citibank customers' accounts are at risk as a result of what the London Times is calling the "biggest and most effective remote PIN code theft scam in US banking history."

Previous Article « The “Receipt for Your Payment to” eBay Paypal Phishing Spam
Read Next Article » Happy Independence Day from The Internet Patrol!

  Follow Anne on Twitter     Friend Anne on Facebook

A breaking news report (why is it breaking in England, not here in the U.S.?) reveals that millions of Citibank customers’ accounts are at risk as a result of what the London Times is calling the “biggest and most effective remote PIN code theft scam in US banking history.”

According to the report, “Citibank machines in 7-Eleven convenience stores across America were the target,” and already more than $2million has been drained from Citibank customers’ accounts.

The situation came to light only because the original perpetrators have been caught, and are now in custody, and wending their way through the U.S. court system. But the hacking into accounts was continuing at least into this spring, and of course we all know that lists of PIN codes - like email addresses - can be sold. Meaning that there is a high probability that the stolen PIN numbers are still in the hands of someone who will use them maliciously - and, if you are a Citibank customer, it’s time to go over your statements for the last several months with a fine-toothed comb, and for goodness sake change your PIN number!

The report blames the situation on the fact that the ATM infrastructure “is now built on Microsoft’s Windows operating system, and the cash machines themselves can be remotely diagnosed and repaired online. Unfortunately, this means that PIN codes have started to “leak” along the way — suggesting that industry guidelines on encryption are not always being followed.”

Of course, we predicted this 3 1/2 years ago, when it was first announced that thousands of ATMs in the United States were being moved to a Windows platform, and again just four months later when Wells Fargo announced they had moved their ATMs to the Windows platform.

Apparently Citibank did too, much to the detriment of their users, it is now clear.

Of the news of the Citibank PIN exposure Gartner security analyst Avivah Litan said “PINs were supposed be sacrosanct. What this shows is that PINs aren’t always encrypted like they’re supposed to be. The banks need much better fraud detection systems and much better authentication.”

Ironically, it was Litan who said, back four years ago, that “the move to Windows-based ATM systems is “not great news for the security of the system. I’m sure there’s a lot of holes that will be created because of this.’ ”

According to the times, it is not yet clear exactly how many Citibank customers have already been affected by this. There are more than 5600 Citibank ATMs in 7-Eleven stores across the U.S..

According to Don Jackson, director of threat intelligence for the computer security company SecureWorks, the only thing that really makes the Citibank PIN hacking case unique is that the guys were caught. Citing an alarming spike in the number of such hacks in the past year, Jackson said that there are “a whole lot of other PIN compromises going on that aren’t reported.”

Citibank has refused to comment on the situation, other than to say “We want our customers to know that, consistent with legal requirements, we do not hold them responsible for fraudulent activity in their accounts.”

They had bloody well better not, given that it’s their fault for setting up their ATM network on such an inherently - indeed predictably - insecure platform.

Millions of Citibank Customers at Risk Due to Largest PIN Number Hacking in History

 Follow Anne on Twitter

 Twitter Explained in Plain English

 Friend Anne on Facebook

Previous Article « The “Receipt for Your Payment to” eBay Paypal Phishing Spam
Read Next Article » Happy Independence Day from The Internet Patrol!

Read more:

»  ChoicePoint Sued Over Hacking, Identity Theft

»  ChoicePoint Syndrome: Lexis Nexis Hemorrhages Personal Information of Thousands to Identity Thieves

»  Identity Theft Insurance Now Available

»  How to Delete Internet History and Search History from Internet Explorer, Safari, IE7, Firefox and Google Toolbar

For additional similar stories check out our archives on Hacking

NOTE: We never, ever, ever will recommend any product or service on this site that we have not regularly used ourselves and do not wholeheartedly believe in. That said, in some cases after being very pleased with a product or service, we may enter into a relationship with the provider of that product or service such that if someone purchases that product or service based on our recommendation, we may get a small payment. Such payments go towards the upkeep of the Internet Patrol.

 

No Comments »

No comments yet.

RSS feed for comments on this post.

Leave a comment

Warning! All comments which contain URLs and are clearly just spam to generate a link back to the URL will be deleted on sight. Don't bother wasting your time!

If you are going to include a URL in your comment,
please keep it under 25 characters in length,
or use TinyURL to shorten it before including it in your comment.

Line and paragraph breaks are automatic, your email address is never displayed.
HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

(required)

(required)


If you have not posted a comment here before, we apologize for having to ask you to enter the letters and numbers you see in the image above to validate your comment, but we are being attacked by thousands of comment form spams every day! You only need to do this once; once you have successfuly posted a comment here you will not be asked to do this again. Thank you for your understanding!

 
 This article first appeared on 7/3/2008
The Internet Patrol
Patrolling the Internet for You!