New Credit Card Scam

Current Berkman People and Projects 2016-05-14

Summary:

A criminal ring was arrested in Malaysia for credit card fraud:

They would visit the online shopping websites and purchase all their items using phony credit card details while the debugging app was activated.

The app would fetch the transaction data from the bank to the online shopping website, and trick the website into believing that the transaction was approved, when in reality, it had been declined by the bank.

The syndicates would later sell the items they had purchased illegally for a much lower price.

The problem here seems to be bad systems design. Why should the user be able to spoof the merchant's verification protocol with the bank?

Link:

https://www.schneier.com/blog/archives/2016/05/new_credit_card.html

From feeds:

Gudgeon and gist » Schneier on Security
Fair Use Tracker » Current Berkman People and Projects
Berkman Center Community - Test » Schneier on Security

Tags:

securityengineering scams fraud creditcards authentication

Authors:

schneier

Date tagged:

05/14/2016, 15:52

Date published:

05/11/2016, 07:34