<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: arco]]></title>
    <link>http://securityratty.com/tag/arco</link>
    <description></description>
    <pubDate>Thu, 27 Dec 2007 10:58:30 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Card skimming at Lunardi's Supermarket]]></title>
      <link>http://securityratty.com/article/06067c47cf83ba97ea6c15e558901e84</link>
      <guid>http://securityratty.com/article/06067c47cf83ba97ea6c15e558901e84</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
4/29/08

Organization
Lunardi's

Contractor/Consultant/Branch
None

Victims
Customers

Number Affected
Unknown

Types of Data
bank card numbers and...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/lunardis.jpg" align="right" height="55" width="200"><font size="2"><b>Date Reported: </b><br>4/29/08<br><br><b>Organization: </b><br><a href="http://www.lunardis.com/home.html">Lunardi's</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>Customers<br><br><span style="font-weight: bold;">Number Affected:</span><br>Unknown<br><br><span style="font-weight: bold;">Types of Data:</span><br>"bank card numbers and personal identification codes"*<br><br><font size="1">*bank cards include credit cards and debit cards</font><br><br><span style="font-weight: bold;">Breach Description:</span><br>"About 150 people who used their bank debit cards at a Lunardi's Supermarket in Los Gatos have become victims of an identity theft scam.&nbsp; And that number is expected to grow, Los Gatos police Capt. Dave Gravel said."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://cbs5.com/localwire/22.0.html?type=bcn&amp;item=THEFT-IDENTITY">KPIX TV Channel 5</a> <br><a href="http://www.mercurynews.com/localnewsheadlines/ci_9103949">The Mercury News</a> <br><a href="http://www.mercurynews.com/breakingnews/ci_9133648?nclick_check=1">The Mercury News (update)</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>KPIX TV Channel 5<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>An ATM and credit card reader in a checkout aisle at the Los Gatos Lunardi's supermarket was recently switched, resulting in more than two dozen reported cases of identity theft, a Los Gatos/Monte Sereno Police Department spokesman said today.<br><span style="font-style: italic;">[Evan] The number "two dozen" was used in the original report on April 29th.</span><br><br>About 150 people who used their bank debit cards at a Lunardi's Supermarket in Los Gatos have become victims of an identity theft scam.<br><span style="font-style: italic;">[Evan] By the time of the May 2nd story, the number of reported cases grew to about 150.</span><br><br>And that number is expected to grow, Los Gatos police Capt. Dave Gravel said.<br><br>Police received the first reports from victims who said their credit or debit cards had been used fraudulently on Sunday night and additional victim reports continued on Monday and today, according to police spokesman Tam McCarty.<br><br>Police believe the victims all had their card numbers stolen at the Los Gatos Lunardi's, 720 Blossom Hill Road, after officials from Lunardi's contacted them about a problem with one of their card readers.<br><br>"It was a switched card reader at one of the aisles,'' McCarty said.<br><br>"What we have here is more than one person - they've been able to get in there (Lunardi's) and switch out the ATM card reader," said Los Gatos-Monte Sereno police Sgt. Tam McCarty. "Once they've done that they can read the card and PIN numbers and either make a temporary card or sell the numbers over the phone."<br><span style="font-style: italic;">[Evan] Completely switch out the card reader?&nbsp; I have never been to the store so I don't know the layout, but how does a person switch out a card reader during business hours without anyone noticing?&nbsp; It seems very risky to make the switch during business hours.&nbsp; I suppose that a thief could pose as a repair or other support person that wouldn't look suspect. Was the switch done while the store was closed?&nbsp; If so, this seems to imply an insider.&nbsp; Just thoughts, I am sure that the investigators have already thought through these questions.</span><br><br>The thieves then transferred that bank information onto cloned cards - any card with a magnetic stripe can be used - and made cash withdrawals from ATMs in Southern California.<br><span style="font-style: italic;">[Evan] Search Google for "</span><a style="font-style: italic;" href="http://www.google.com/search?hl=en&amp;client=firefox-a&amp;rls=org.mozilla%3Aen-US%3Aofficial&amp;hs=ksN&amp;q=credit+card+encoder&amp;btnG=Search">Credit Card Encoder</a><span style="font-style: italic;">" and take your pick of various credit/debit card magnetic stripe readers/writers.&nbsp; Extreme Media has information on "Credit Card Hacking, ATM Hacking, Debit Card Hacking and more. From Identity Fraud to Off Shore Banking we have you covered."&nbsp; I have never used or read any of their wares, so I don't know how reliable it is.&nbsp; The point I am trying to make is that committing fraud with compromised credit/debit card information is easy and there are plenty of people willing to help the bad guys.</span><br><br>police are still trying to determine how much money was stolen.<br><br>Recent shoppers of the Los Gatos Lunardi's should check the status of their bank or credit card accounts for charges they did not make, according to police.<br><span style="font-style: italic;">[Evan] If I were a customer of Lunardi's, I would contact my bank and close my credit/debit card account and open a new one (with new numbers).</span><br><br>Through an attorney, the Lunardi family, which owns the upscale grocery chain, also declined to discuss specifics about the technology used.<br><br>In a statement, the owners said the chain "in no way wants to compromise the ongoing investigation by law enforcement authorities or to reveal details of our security measures which could counteract their effectiveness."<br><br>George Silvestri, an attorney for Lunardi's, said the chain has replaced the payment devices at all seven of its Bay Area locations with machines that are locked onto the checkout stands.<br><br>Lunardi's employees with access to these devices have been trained in security procedures recommended by law enforcement and banking authorities.<br><br>Anyone who finds fraudulent charges on an account should contact the local police department or the Los Gatos/Monte Sereno Police Department at (408) 354-8600.<br><br>The thefts at Lunardi's in Los Gatos comes about three weeks after police uncovered a similar scam at an Arco AM/PM in Los Altos.<br><span style="font-style: italic;">[Evan] I missed this specific breach, but I did report an ARCO "skimming" related <a href="http://breachblog.com/2007/12/27/arco.aspx">breach</a> in December, 2007.&nbsp; The December breach occurred at the El Monte station.</span><br><br><span style="font-weight: bold;">Commentary:</span><br>Card skimming is nothing new, but the methods have been refined and the technology has gotten better.&nbsp; The devices used by the criminals used to be pretty easy to identify, but now some of the devices are so small and well made that it can be difficult to notice, even to a trained eye.&nbsp; <br><br>A video or two might be helpful to readers (good information, but nothing earth shattering)<br><br>An NBC 10 News report:<br><object height="355" width="425"><param name="movie" value="http://www.youtube.com/v/m3qK46L2b_c&amp;hl=en"><param name="wmode" value="transparent"><embed src="http://www.youtube.com/v/m3qK46L2b_c&amp;hl=en" type="application/x-shockwave-flash" wmode="transparent" height="355" width="425"></object><br><br>From the UK, "The Real Hustle - ATM Scam"<br><object height="355" width="425"><param name="movie" value="http://www.youtube.com/v/6Zq1oIq87pY&amp;hl=en"><param name="wmode" value="transparent"><embed src="http://www.youtube.com/v/6Zq1oIq87pY&amp;hl=en" type="application/x-shockwave-flash" wmode="transparent" height="355" width="425"></object> <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/05/06/lunardis.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Tue, 06 May 2008 08:25:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/credit card reader">credit card reader</category>
      <category domain="http://securityratty.com/tag/credit">credit</category>
      <category domain="http://securityratty.com/tag/credit card accounts">credit card accounts</category>
      <category domain="http://securityratty.com/tag/credit card">credit card</category>
      <category domain="http://securityratty.com/tag/debit cards">debit cards</category>
      <category domain="http://securityratty.com/tag/cards">cards</category>
      <category domain="http://securityratty.com/tag/card">card</category>
      <category domain="http://securityratty.com/tag/credit card encoder">credit card encoder</category>
      <category domain="http://securityratty.com/tag/bank debit cards">bank debit cards</category>
      <source url="http://breachblog.com/2008/05/06/lunardis.aspx">Card skimming at Lunardi's Supermarket</source>
    </item>
    <item>
      <title><![CDATA[ARCO gas pumps targeted by fraudsters]]></title>
      <link>http://securityratty.com/article/969df5ce69bf4b4dae8480b66d2150a0</link>
      <guid>http://securityratty.com/article/969df5ce69bf4b4dae8480b66d2150a0</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
12/12/07

Organization
ARCO

Contractor/Consultant/Branch
Station located at 4378 N. Santa Anita Avenue, El Monte, California

There are 135 ARCO gas...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/arco.jpg" align="right" height="39" width="127">
<font size="2"><span style="font-weight: bold;">Date Reported: </span><br>12/12/07<br><br><span style="font-weight: bold;">Organization: </span><br>ARCO<br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.arco.com/toolserver/arcotool/routeplannerstationdetails.do?fuelstationid=81844&amp;state=0" target="_blank"> Station located at 4378 N. Santa Anita Avenue, El Monte, California</a>*<br><br><font size="1">*There are 135 ARCO gas stations within a 10 mile radius</font><br><br><span style="font-weight: bold;">Victims:</span><br>ARCO Customers<br><br><span style="font-weight: bold;">Number Affected:</span><br>As many as 100<br><br><span style="font-weight: bold;">Types of Data:</span><br>Debit card magnetic stripe data and PINs (Personal Identification Numbers).<br><br><span style="font-weight: bold;">Breach Description:</span><br>It appears as though a group of thieves has installed an unknown electronic data capture device on one or more gas pumps at one or more ARCO gas stations for the purpose of stealing customers' money.&nbsp; Monetary losses have already surpassed $30,000, with unauthorized withdrawls taking place all across the U.S.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.msnbc.msn.com/id/22217540/" target="_blank"> KNBC-TV News Story</a><br><a href="http://cbs2.com/local/ID.Theft.Investigation.2.609494.html" target="_blank"> KCAL 9 News Story</a><br><a href="http://www.whittierdailynews.com/news/ci_7727859" target="_blank"> Whittier Daily News Story</a><br><br><span style="font-weight: bold;">Report Credit:</span><br>KNBC-TV<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>Law enforcement authorities are searching for whoever skimmed debit card information from at least 45 customers at an Arco station in El Monte<br><br>The suspects made off with thousands of dollars from unsuspecting customers. A computerized device apparently was used to lift key information, including debit card identification numbers, concealed in the card's magnetic strip<br><span style="font-style: italic;">[Evan] It never ceases to amaze me how clever thieves are.&nbsp; I would love to see the device that was used, how they installed it, how they concealed it, and how they stored the information that they captured.&nbsp; This isn't just some "run-of-the-mill" street thug.</span><br style="font-style: italic;"><br>Fraudulent withdrawals, ranging from $400 to $1,500 per customer, were made in Las Vegas, Palms Springs and New York, police said. Investigator Victor Hernandez told the San Gabriel Valley Tribune there could be as many as 100 victims.<br><br>The reported monetary losses had also jumped from $10,000 to $30,000 - and Glick said that number could reach $100,000 once all of the cases are investigated. <br><br>No illegal devices have been found at the gas station, but authorities say the fact that all the victims have used their cards there is more than a "coincidence." <br><br>investigators believe an advanced computer device was used to capture information from cards' electronic strips and personal identification numbers (PIN). <br><br>a group of people are likely behind this debit-card scam because withdrawals are being made simultaneously in locations hundreds, sometimes thousands, of miles away from one another.<br><span style="font-style: italic;">[Evan] Maybe.&nbsp; I wouldn't base this assumption solely on where the information was used, per se.&nbsp; There is a thriving market in fresh stolen credit/debit card data.&nbsp; The compromised information could have been stolen months ago, then recently sold on one of many "carders" forums.</span><br style="font-style: italic;"><br>"There seems to be more ARCO gas stations than other gas stations targeted," Glick said. "It's possible a specific group or groups are working these pumps." <br><span style="font-style: italic;">[Evan] Incidents like this breach could/should force gas stations and other unattended payment merchants to rethink how they secure their terminals.&nbsp; The convenience is great, but security of the information is more important.</span><br><br>ARCO officials said the company only accepts debit cards because banks impose higher fees for credit transactions.<br><br>"ARCO considers the safety and security of every customer a top priority," said Todd Spitler, a spokesman for the company. "But there are other businesses throughout California, not only us, that only accept debit cards." <br><br>The company often updates its technology to thwart criminal activity, and any time their pumps are compromised, ARCO officials work with law enforcement agencies, Spitler said. But identity theft is a global issue, he said.<br><em>[Evan] This isn't identity theft, this is credit card fraud.</em><br><br><span style="font-weight: bold;">Victim Response:</span><br>From El Monte resident Douglas Trujillo, a victim of $1,100:<br>"I do online banking and I looked at my account and I noticed my checking account at zero dollars," he said. "That set alarms off for me." <br><br>"I'm actually going to change my whole process," Trujillo said. "Now that I've seen how easy (thieves) can do this, I'm just going to stick to using cash and secure ATMs."<br><br><span style="font-weight: bold;">Commentary:</span><br>This is a very unfortunate, but at the same time interesting breach.&nbsp; I would love to know more about how the ARCO gas pumps are secured and how they transmit data.&nbsp; I would also love to know more about how the data was actually compromised.&nbsp; I have to admit, this breach makes me think more about paying at the pump.&nbsp; I expect to read about similar breaches in the future.&nbsp; Sad but true. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2007/12/27/arco.aspx" type="text/javascript" charset="utf-8"></script>
<br>
<br>
<script type="text/javascript"><!--
google_ad_client = "pub-4721162729073131";
google_ad_width = 468;
google_ad_height = 60;
google_ad_format = "468x60_as";
google_ad_type = "text_image";
google_ad_channel = "";
//-->
</script>
<script type="text/javascript">
</script>]]></content:encoded>
      <pubDate>Thu, 27 Dec 2007 10:58:30 +0000</pubDate>
      <category domain="http://securityratty.com/tag/arco gas pumps">arco gas pumps</category>
      <category domain="http://securityratty.com/tag/pumps">pumps</category>
      <category domain="http://securityratty.com/tag/gas pumps">gas pumps</category>
      <category domain="http://securityratty.com/tag/arco">arco</category>
      <category domain="http://securityratty.com/tag/gas stations">gas stations</category>
      <category domain="http://securityratty.com/tag/arco gas stations">arco gas stations</category>
      <category domain="http://securityratty.com/tag/card">card</category>
      <category domain="http://securityratty.com/tag/debit card identification">debit card identification</category>
      <category domain="http://securityratty.com/tag/creditdebit card data">creditdebit card data</category>
      <source url="http://breachblog.com/2007/12/27/arco.aspx">ARCO gas pumps targeted by fraudsters</source>
    </item>
  </channel>
</rss>
