Login Register


Hackers Now Using Shimmers To Steal CC Information filter_list
Author
Message
Hackers Now Using Shimmers To Steal CC Information #1
Greetings to all,

Irrespective of measures In place to protect our credentials, from both a technological and human awareness & best practice standpoint, there's always a way to circumvent the security of any Implementation. Hackers are now using a method named "shimming" to steal credit card Information.

Quote:Hackers have found a way around those chip-enabled credit cards designed to protect your information. You’ve heard of skimming, and now, officials are warning about credit card “shimming.”

“Shimming is just a new way of scammers being able to steal credit card information,” said Bryan Oglesby, Better Business Bureau.

Here’s how it works: Scammers insert a thin device with a microchip and flash storage into the slot where you slide your credit card with those new chips. The “shim,” as it’s called, copies and saves your information. By the time you find out, it’s too late.

Source.
[Image: AD83g1A.png]

Reply

RE: Hackers Now Using Shimmers To Steal CC Information #2
It was only a matter of time before it happened, stay safe out there.

Reply

RE: Hackers Now Using Shimmers To Steal CC Information #3
In my opinion, credit card chips have been almost a faliure in the US. I say almost, because they have worked, but it's often a headache for companies, as registers always have issues with them, so many (including large) companies just don't use them, and use the normal stripe.

Maybe 'barely a success' is more accurate...
(This post was last modified: 05-07-2018, 04:03 PM by Blink.)


(11-02-2018, 02:51 AM)Skullmeat Wrote: Ok, there no real practical reason for doing this, but that's never stopped me.

Reply

RE: Hackers Now Using Shimmers To Steal CC Information #4
(05-07-2018, 04:02 PM)Ender Wrote: credit card chips have been almost a faliure in the US. I say almost, because they have worked, but it's often a headache for companies, as registers always have issues with them

Agree.

The same continues to happen In my locality. Just the other week, after repeated failure using the chip, one guy at the register was sifting through his cards to locate one with a normal swipe. I still use the latter with hardly any Issues.
[Image: AD83g1A.png]

[+] 1 user Likes mothered's post
Reply

RE: Hackers Now Using Shimmers To Steal CC Information #5
(05-07-2018, 04:13 PM)mothered Wrote:
(05-07-2018, 04:02 PM)Ender Wrote: credit card chips have been almost a faliure in the US. I say almost, because they have worked, but it's often a headache for companies, as registers always have issues with them

Agree.

The same continues to happen In my locality. Just the other week, after repeated failure using the chip, one guy at the register was sifting through his cards to locate one with a normal swipe. I still use the latter with hardly any Issues.

It would've been better if 2FA was implemented with credit cards, or even if they were replaced with One Time Password cards (think RSA keychains or GAuth).
(This post was last modified: 05-07-2018, 06:55 PM by Blink.)


(11-02-2018, 02:51 AM)Skullmeat Wrote: Ok, there no real practical reason for doing this, but that's never stopped me.

Reply

RE: Hackers Now Using Shimmers To Steal CC Information #6
I suspect Defcon's ATMs will be no different this year.
[Image: 7ajmN5P.jpg]

Telegram: Oni_SL (Link)

Reply

RE: Hackers Now Using Shimmers To Steal CC Information #7
I'm totally not surprised. Criminals find new ways to steal our credentials and personal information. I just hope the police will soon learn how to catch up to those criminals.

Reply

RE: Hackers Now Using Shimmers To Steal CC Information #8
This is a bad thing, but similar techniques have been used before. In my country, they recently found out that cards with wireless payment in them (pretty much standard here), are very easy to empty.

Here is the scenario, basically, you can pay every amount < 25€ without having to enter a pin code or do any verification. They did a test, where a person with a payment device would wrap it in a newspaper and bump against various strangers. Often if it was close enough to their pockets/purses they were able to receive the money directly on their bank without a problem.

Security is getting harder and harder and I think the next move they'll need to make is create biometric login systems (yes, it already exists), but I mean making it in a standard instead of passwords. Once quantum computing is here, hash cracking would be made easy, and most security we know nowadays would fail.
~~ Might be back? ~~

Reply

RE: Hackers Now Using Shimmers To Steal CC Information #9
(05-08-2018, 07:57 PM)Bish0pQ Wrote: In my country, they recently found out that cards with wireless payment in them (pretty much standard here), are very easy to empty.

Here is the scenario, basically, you can pay every amount < 25€ without having to enter a pin code or do any verification. They did a test, where a person with a payment device would wrap it in a newspaper and bump against various strangers. Often if it was close enough to their pockets/purses they were able to receive the money directly on their bank without a problem.

Very clever. The main Issue Is, you need to Identify exactly which strangers do In fact hold wireless payment cards.

This just demonstrates that anything via wireless transmission, Is susceptible to attack and exploitation.


(05-08-2018, 07:57 PM)Bish0pQ Wrote: Security is getting harder and harder and I think the next move they'll need to make is create biometric login systems (yes, it already exists), but I mean making it in a standard instead of passwords.

Biometric authentication Is certainly a lot more secure, but not foolproof.

For Instance, take fingerprint authentication on a given device. Because fingerprint scanners are so small, they only take partial prints. As such, "full" human fingerprints are almost Impossible to match. So the device takes and stores so many "partial" prints- just to make It easier to find a match. Ultimately, a finger swipe only has to match ONE PARTIAL stored Image, hence a mismatch can happen with anyone's fingerprint.

An analogy Is If you store 10 passwords, and a hacker only has to match just the one with the list of passwords at his disposal.

When the police apprehend a criminal and take prints, you'll notice they "roll" the finger against the Ink- to make sure the ENTIRE finger Is printed. Fingerprint scanners (obviously) cannot do this, hence my above post.
[Image: AD83g1A.png]

Reply







Users browsing this thread: