Commentary

George Hulme
 

UAE Bank Breach Spreads

International investigators still aren't sure, or they're not saying, how criminals managed to generate counterfeit bank and credit cards of legitimate users and conduct fraudulent charges from about 20 countries.

International investigators still aren't sure, or they're not saying, how criminals managed to generate counterfeit bank and credit cards of legitimate users and conduct fraudulent charges from about 20 countries.Earlier this month, Abu Dhabi-based newspaper The National wrote a story about an international investigation under way for criminals alleged to have obtained account information from UAE-based financial services companies. From that story:

The scheme came to light after a number of employees at the U.S. Embassy -- and a handful of other US citizens -- had unauthorized purchases show up on their credit and debit cards in recent months, prompting the embassy to issue a warning on its Web site.

More Security Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

"To date, all of the reported fraudulent charges have been made from the United States," the message said. "We are aware of no fraudulent transactions originating in the UAE."

That story postulates that criminals had perhaps infiltrated the servers of a payment processor. But a story that ran Saturday in Times Online indicates that automated teller machines may have been compromised to swipe customer information as they access the machines:

The lenders declined to say how much money had been stolen or how many accounts were skimmed, but an initial investigation by the banks indicated that cash machines were rigged with devices that stole customers' PINs as they made withdrawals.

Suvo Sarkar, general manager of retail banking at Emirates NBD told the Times Online that authorities still aren't sure how the account numbers and card PINs were nabbed:

Mr. Sakar said that the hackers were part of an international network, with most of the fraudulent transactions originating from more than 20 countries outside the UAE.

The banks affected include HSBC, Citibank, Lloyds TSB, National Bank of Abu Dhabi, and Emirates NBD.

It's impossible to tell how the breach occurred. My bet, based on similar incidents that plagued U.S. banks earlier this decade -- before banks and retailers stopped systemically storing PINs -- is that a payment card processor or major retailer was successfully hacked.

Best action, just like passwords, is to periodically change them.

What steps do you take to mitigate yourself from such incidents? Or do you use the same password for the majority of Web sites you access, and do you use the same PIN number that you use to access your voice mail for all of your credit and bank cards? I hope not, because you're begging for trouble if you do.


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links