Central American gang believed to be behind massive credit card security breach

Share this article

The financial news media is abuzz with the latest massive security breach of a computer system containing sensitive credit and debit account information.

A security analyst at Gartner, one of the world’s leading information technology research and advisory company, reported on March 30th that she heard “the crime was perpetrated by a Central American gang that broke into the company’s system by answering the application’s knowledge based authentication questions correctly.”

Avivah Litan is listed as a VP and Distinguished analyst at Gartner. She also indicated that the participation of a Central American gang “may not be factual.”

Ms. Litan was referring to an announcement made by Global Payments, an American processor of credit card payments, that their security had been compromised by hackers. On that day, the Visa and MasterCard networks had been busy notifying some of their cardholders of the breach. Respected security analyst Brian Krebs also heard that “that this breach may be somehow connected to Dominican street gangs in and around New York City. This comes from two reliable sources.”

Back to Ms. Litan, she explains that:

“From what I hear, the breach involves a taxi and parking garage company in the New York City area so if you’ve paid a NYC cab in the last few months with your credit or debit card – be sure to check your card statements for possible fraud.”

It is important to note that the sources behind the reports of criminal gang activity and their ethnicity or regional allegiance on this breach, which reportedly involves 10 million credit and debit card accounts, have not been confirmed.

Between the two takes on the breach, some very interesting details emerge. The first is Ms. Litan’s unconfirmed report that hackers working for the Central American gang gained access to a computer system that held the compromised information by:

“answering the application’s knowledge based authentication questions correctly. Looks like the hackers took over an administrative account that was not protected sufficiently.”

Many of us are probably familiar with knowledge-based authentication (KBA) processes. A KBA process asks a computer user to answer a series of personal questions in addition to choosing a combination of username and password to log into a computer system. These questions typically include mother’s maiden name, favorite pet, birth city, location of honeymoon, favorite sports team, etc.

It isn’t clear how the hackers could have penetrated that layer of security, or whether this was an inside job. It is also unclear for how long the alleged taxi and parking company held on to credit and debit transaction data. Ten million accounts is a significant number for any merchant.

Mr. Krebs goes on to explain that a provider of online financial services to credit unions had notified 482 institutions of the breach, and that more than 55,000 Visa and MasterCard accounts were affected, but only 876 accounts had been used for fraud thus far. Account holders will not be liable for fraudulent use of their cards.

The Wall Street Journal reported that massive credit card breaches have been on the rise since 2005, with one of the most severe cases happening in 2009 -against Heartland Payment Systems in the United States. That breach affected over 100 million accounts.

Print Friendly, PDF & Email

Comments