News >> Browse Articles >> Security

+5

Citibank ATM Breach Reveals PIN Security Problems

Citibank ATM Breach Reveals PIN Security Problems

Jordan Robertson / Associated Press

July 01, 2008

SAN JOSE, CA – Hackers broke into Citibank’s network of ATMs inside 7-Eleven stores and stole customers’ PIN codes, according to recent court filings that revealed a disturbing security hole in the most sensitive part of a banking record.

The scam netted the alleged identity thieves millions of dollars. But more importantly for consumers, it indicates criminals were able to access PINs – the numeric passwords that theoretically are among the most closely guarded elements of banking transactions – by attacking the back-end computers responsible for approving the cash withdrawals.

The case against three people in U.S. District Court for the Southern District of New York highlights a significant problem.

Hackers are targeting the ATM system’s infrastructure, which is increasingly built on Microsoft Corp.‘s Windows operating system and allows machines to be remotely diagnosed and repaired over the Internet. And despite industry standards that call for protecting PINs with strong encryption – which means encoding them to cloak them to outsiders – some ATM operators apparently aren’t properly doing that. The PINs seem to be leaking while in transit between the automated teller machines and the computers that process the transactions.

“PINs were supposed be sacrosanct – what this shows is that PINs aren’t always encrypted like they’re supposed to be,” said Avivah Litan, a security analyst with the Gartner research firm. “The banks need much better fraud detection systems and much better authentication.”

It’s unclear how many Citibank customers were affected by the breach, which extended at least from October 2007 to March of this year and was first reported by technology news Web site Wired.com. The bank has nearly 5,700 Citibank-branded ATMs inside 7-Eleven Inc. stores throughout the U.S., but it doesn’t own or operate any of them.

That responsibility falls on two companies: Houston-based Cardtronics Inc., which owns all the machines but only operates some, and Brookfield, Wis.-based Fiserv Inc., which operates the others.

A critical issue in the investigation is how the hackers infiltrated the system, a question that still hasn’t been answered publicly.

All that’s known is they broke into the ATM network through a server at a third-party processor, which means they probably didn’t have to touch the ATMs at all to pull off the heist.

They could have gained administrative access to the machines – which means they had carte blanche to grab information – through a flaw in the network or by figuring out those computers’ passwords. Or it’s possible they installed a piece of malicious software on a banking server to capture unencrypted PINs as they passed through.

What that means for consumers is that their PINs were stolen from machines that showed no signs of tampering they could detect. In previous PIN thefts, thieves generally took steps that might draw notice – sending “phishing” e-mails, for example, or installing false-front keypads or even tiny cameras on ATMs.


+5
  • Photo_user_blank_big

    cjsoileau

    11 months ago

    2 comments

    Here's an idea use cash....

  • Photo_user_blank_big

    ebin

    11 months ago

    2 comments

    hey .....this is very clear that the banking ATM DEVELOPED BY THE COMPANY is not best enough to avoid intruders.The programing might have a flaw that WOULD HAVE SUPPORTED the hackers to succeed without even touching ATM.probably i beleive that the company must be responsible in updating the programming technique since the intruders are always there in excperting the technology and techniques.so they should be prepared IN UPDATING THE TECHNIQUES DEPENDING UPON THE DEPTH OF THE SOFTWARE...

  • Dsc01215_max50

    sgtcelella

    11 months ago

    10 comments

    Where every there is thievery involved, there is Chase bank. Chase has made their fortune off of the backs of the hard working. Christ JP Morgan is famous for usurping the government into a federal reserve system. This "fraud" is synthetically created to facilitate the future of personal banking and identity; the R.F. chip. Wont be long before stupid, scared people are begging to be chipped.

  • 01_max50

    Duttymonk

    11 months ago

    4 comments

    Chase bank has been doing this for years in a partnership with thieves in Verizon payroll. I currently have a lawsuit filed against Verizon for this as we speak and Chase will be getting their lawsuit very soon. The sad part about this is Chase and Verizon have been doing this for years. Verizon steals the salary of its employees & chase helps them do it and I have the proof.

  • Z16ph9ea_max50

    dhananjaybisen

    11 months ago

    2 comments

    where is security related top institute

  • 25042007041_max50

    fayaz

    11 months ago

    4 comments

    well what i think is that Linux is secure but it is also hacked now.. so what i will suggest that they should use Sun Solarise operatiing system.. and should use advance encryption standards. although it will slow the process abit because of decryption and encryption of the pin code but still it is very secure

  • T08_240x400_max50

    shubhm

    11 months ago

    2 comments

    I agree with ghendric.. the banking industry should use Linux with XWindows which has GUI frontend and safeboot encryption technology..

  • Char_george_max50

    ghendric

    11 months ago

    6 comments

    The banking industry should be using something else like Linux or Unix for stuff like this. Not frickin' Winders... geezz..

  • 1233_max50

    asake

    11 months ago

    2 comments

    good job

  • Photo_user_blank_big

    aseemvashisht

    11 months ago

    2 comments

    upgradation of systems is very important .this is age of technology

  • Photo_user_blank_big

    BBgun

    11 months ago

    2 comments

    This is what Happens when you trust the Evil Lord Bill gates and ANY Microsoft Product!
    HA! Too Funny! Maybe Microsoft should be held responsible and pay back any stolen monies.......HMMMMM?

  • Imgp0418_max50

    Dustin16

    11 months ago

    4 comments

    Security Schmurity....Whoohahahahahah

  • Ham_max50

    jonesam

    11 months ago

    10 comments

    LOL ask a bunch of nerds to respond and you get the following and the above. Dang it you guys make life fun as hel. Pround to be a geek

  • Hopper_on_orange_marigold_max50

    BugaBoo

    11 months ago

    40 comments

    Caveat emptor: Buyer beware! We need always to be on guard. This includes the companies, too.

  • New_challenger_max50

    Paulscr1

    11 months ago

    100 comments

    If you CHEAP FCKRS Hired me along time ago that would have never happend
    LMFAO

What's the Scoop?

Post a link to something interesting from another site, or submit your own original writing for the InsideTech community to read.

Report News Here

IT Career Advice

Sf-skyline-main_sq32

Top 25 Cities for Tech Jobs

Now more than ever, it’s important to get the best bang for your buck. And there’s no question about ...

Hotcareers-250_sq32

10 Recession-Proof IT Careers

Companies are cutting back spending, shrinking staff sizes, and making tough layoffs at a rate that most of us ...

50books_sq32

50 Books Every Geek Should Read

Ever find out one of your friends hasn't read "Neuromancer" or doesn't know what a Babelfish is or why ...

Recent Activity

Nb_max30
deepu299 submitted the article: "The Paperless Office", 12 minutes ago.
Nb_max30
deepu299 submitted the article: "Which Airlines Have Wi-Fi?", 15 minutes ago.
Nb_max30
deepu299 commented on: "raghu reddy", 18 minutes ago.
Nb_max30
deepu299 commented on: "Bhavini Shah", 19 minutes ago.
Nb_max30
deepu299 submitted the article: "First look: Microsoft Office 2010", 22 minutes ago.