<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: pumps]]></title>
    <link>http://securityratty.com/tag/pumps</link>
    <description></description>
    <pubDate>Thu, 27 Dec 2007 10:58:30 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[ARCO gas pumps targeted by fraudsters]]></title>
      <link>http://securityratty.com/article/969df5ce69bf4b4dae8480b66d2150a0</link>
      <guid>http://securityratty.com/article/969df5ce69bf4b4dae8480b66d2150a0</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
12/12/07

Organization
ARCO

Contractor/Consultant/Branch
Station located at 4378 N. Santa Anita Avenue, El Monte, California

There are 135 ARCO gas...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/arco.jpg" align="right" height="39" width="127">
<font size="2"><span style="font-weight: bold;">Date Reported: </span><br>12/12/07<br><br><span style="font-weight: bold;">Organization: </span><br>ARCO<br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.arco.com/toolserver/arcotool/routeplannerstationdetails.do?fuelstationid=81844&amp;state=0" target="_blank"> Station located at 4378 N. Santa Anita Avenue, El Monte, California</a>*<br><br><font size="1">*There are 135 ARCO gas stations within a 10 mile radius</font><br><br><span style="font-weight: bold;">Victims:</span><br>ARCO Customers<br><br><span style="font-weight: bold;">Number Affected:</span><br>As many as 100<br><br><span style="font-weight: bold;">Types of Data:</span><br>Debit card magnetic stripe data and PINs (Personal Identification Numbers).<br><br><span style="font-weight: bold;">Breach Description:</span><br>It appears as though a group of thieves has installed an unknown electronic data capture device on one or more gas pumps at one or more ARCO gas stations for the purpose of stealing customers' money.&nbsp; Monetary losses have already surpassed $30,000, with unauthorized withdrawls taking place all across the U.S.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.msnbc.msn.com/id/22217540/" target="_blank"> KNBC-TV News Story</a><br><a href="http://cbs2.com/local/ID.Theft.Investigation.2.609494.html" target="_blank"> KCAL 9 News Story</a><br><a href="http://www.whittierdailynews.com/news/ci_7727859" target="_blank"> Whittier Daily News Story</a><br><br><span style="font-weight: bold;">Report Credit:</span><br>KNBC-TV<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>Law enforcement authorities are searching for whoever skimmed debit card information from at least 45 customers at an Arco station in El Monte<br><br>The suspects made off with thousands of dollars from unsuspecting customers. A computerized device apparently was used to lift key information, including debit card identification numbers, concealed in the card's magnetic strip<br><span style="font-style: italic;">[Evan] It never ceases to amaze me how clever thieves are.&nbsp; I would love to see the device that was used, how they installed it, how they concealed it, and how they stored the information that they captured.&nbsp; This isn't just some "run-of-the-mill" street thug.</span><br style="font-style: italic;"><br>Fraudulent withdrawals, ranging from $400 to $1,500 per customer, were made in Las Vegas, Palms Springs and New York, police said. Investigator Victor Hernandez told the San Gabriel Valley Tribune there could be as many as 100 victims.<br><br>The reported monetary losses had also jumped from $10,000 to $30,000 - and Glick said that number could reach $100,000 once all of the cases are investigated. <br><br>No illegal devices have been found at the gas station, but authorities say the fact that all the victims have used their cards there is more than a "coincidence." <br><br>investigators believe an advanced computer device was used to capture information from cards' electronic strips and personal identification numbers (PIN). <br><br>a group of people are likely behind this debit-card scam because withdrawals are being made simultaneously in locations hundreds, sometimes thousands, of miles away from one another.<br><span style="font-style: italic;">[Evan] Maybe.&nbsp; I wouldn't base this assumption solely on where the information was used, per se.&nbsp; There is a thriving market in fresh stolen credit/debit card data.&nbsp; The compromised information could have been stolen months ago, then recently sold on one of many "carders" forums.</span><br style="font-style: italic;"><br>"There seems to be more ARCO gas stations than other gas stations targeted," Glick said. "It's possible a specific group or groups are working these pumps." <br><span style="font-style: italic;">[Evan] Incidents like this breach could/should force gas stations and other unattended payment merchants to rethink how they secure their terminals.&nbsp; The convenience is great, but security of the information is more important.</span><br><br>ARCO officials said the company only accepts debit cards because banks impose higher fees for credit transactions.<br><br>"ARCO considers the safety and security of every customer a top priority," said Todd Spitler, a spokesman for the company. "But there are other businesses throughout California, not only us, that only accept debit cards." <br><br>The company often updates its technology to thwart criminal activity, and any time their pumps are compromised, ARCO officials work with law enforcement agencies, Spitler said. But identity theft is a global issue, he said.<br><em>[Evan] This isn't identity theft, this is credit card fraud.</em><br><br><span style="font-weight: bold;">Victim Response:</span><br>From El Monte resident Douglas Trujillo, a victim of $1,100:<br>"I do online banking and I looked at my account and I noticed my checking account at zero dollars," he said. "That set alarms off for me." <br><br>"I'm actually going to change my whole process," Trujillo said. "Now that I've seen how easy (thieves) can do this, I'm just going to stick to using cash and secure ATMs."<br><br><span style="font-weight: bold;">Commentary:</span><br>This is a very unfortunate, but at the same time interesting breach.&nbsp; I would love to know more about how the ARCO gas pumps are secured and how they transmit data.&nbsp; I would also love to know more about how the data was actually compromised.&nbsp; I have to admit, this breach makes me think more about paying at the pump.&nbsp; I expect to read about similar breaches in the future.&nbsp; Sad but true. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2007/12/27/arco.aspx" type="text/javascript" charset="utf-8"></script>
<br>
<br>
<script type="text/javascript"><!--
google_ad_client = "pub-4721162729073131";
google_ad_width = 468;
google_ad_height = 60;
google_ad_format = "468x60_as";
google_ad_type = "text_image";
google_ad_channel = "";
//-->
</script>
<script type="text/javascript">
</script>]]></content:encoded>
      <pubDate>Thu, 27 Dec 2007 10:58:30 +0000</pubDate>
      <category domain="http://securityratty.com/tag/arco gas pumps">arco gas pumps</category>
      <category domain="http://securityratty.com/tag/pumps">pumps</category>
      <category domain="http://securityratty.com/tag/gas pumps">gas pumps</category>
      <category domain="http://securityratty.com/tag/arco">arco</category>
      <category domain="http://securityratty.com/tag/gas stations">gas stations</category>
      <category domain="http://securityratty.com/tag/arco gas stations">arco gas stations</category>
      <category domain="http://securityratty.com/tag/card">card</category>
      <category domain="http://securityratty.com/tag/debit card identification">debit card identification</category>
      <category domain="http://securityratty.com/tag/creditdebit card data">creditdebit card data</category>
      <source url="http://breachblog.com/2007/12/27/arco.aspx">ARCO gas pumps targeted by fraudsters</source>
    </item>
  </channel>
</rss>
