News >> Browse Articles >> Security

+5

Citibank ATM Breach Reveals PIN Security Problems

Citibank ATM Breach Reveals PIN Security Problems

Jordan Robertson / Associated Press

July 01, 2008

SAN JOSE, CA – Hackers broke into Citibank’s network of ATMs inside 7-Eleven stores and stole customers’ PIN codes, according to recent court filings that revealed a disturbing security hole in the most sensitive part of a banking record.

The scam netted the alleged identity thieves millions of dollars. But more importantly for consumers, it indicates criminals were able to access PINs – the numeric passwords that theoretically are among the most closely guarded elements of banking transactions – by attacking the back-end computers responsible for approving the cash withdrawals.

The case against three people in U.S. District Court for the Southern District of New York highlights a significant problem.

Hackers are targeting the ATM system’s infrastructure, which is increasingly built on Microsoft Corp.‘s Windows operating system and allows machines to be remotely diagnosed and repaired over the Internet. And despite industry standards that call for protecting PINs with strong encryption – which means encoding them to cloak them to outsiders – some ATM operators apparently aren’t properly doing that. The PINs seem to be leaking while in transit between the automated teller machines and the computers that process the transactions.

“PINs were supposed be sacrosanct – what this shows is that PINs aren’t always encrypted like they’re supposed to be,” said Avivah Litan, a security analyst with the Gartner research firm. “The banks need much better fraud detection systems and much better authentication.”

It’s unclear how many Citibank customers were affected by the breach, which extended at least from October 2007 to March of this year and was first reported by technology news Web site Wired.com. The bank has nearly 5,700 Citibank-branded ATMs inside 7-Eleven Inc. stores throughout the U.S., but it doesn’t own or operate any of them.

That responsibility falls on two companies: Houston-based Cardtronics Inc., which owns all the machines but only operates some, and Brookfield, Wis.-based Fiserv Inc., which operates the others.

A critical issue in the investigation is how the hackers infiltrated the system, a question that still hasn’t been answered publicly.

All that’s known is they broke into the ATM network through a server at a third-party processor, which means they probably didn’t have to touch the ATMs at all to pull off the heist.

They could have gained administrative access to the machines – which means they had carte blanche to grab information – through a flaw in the network or by figuring out those computers’ passwords. Or it’s possible they installed a piece of malicious software on a banking server to capture unencrypted PINs as they passed through.

What that means for consumers is that their PINs were stolen from machines that showed no signs of tampering they could detect. In previous PIN thefts, thieves generally took steps that might draw notice – sending “phishing” e-mails, for example, or installing false-front keypads or even tiny cameras on ATMs.


+5
  • New_challenger_max50

    Paulscr1

    about 1 year ago

    104 comments

    Love it
    LMAO

  • Undead_male120x_max50

    rmelendez3

    about 1 year ago

    44 comments

    nothing is safe in this country?

  • Liquid_cooled2_max50

    terrywhitejr2000

    about 1 year ago

    46 comments

    Cool

What's the Scoop?

Post a link to something interesting from another site, or submit your own original writing for the InsideTech community to read.

Report News Here

IT Career Advice

Sf-skyline-main_sq32

Top 25 Cities for Tech Jobs

Now more than ever, it’s important to get the best bang for your buck. And there’s no question about ...

Hotcareers-250_sq32

10 Recession-Proof IT Careers

Companies are cutting back spending, shrinking staff sizes, and making tough layoffs at a rate that most of us ...

50books_sq32

50 Books Every Geek Should Read

Ever find out one of your friends hasn't read "Neuromancer" or doesn't know what a Babelfish is or why ...

Recent Activity

Photo_user_blank_big
jimwallentine is ranked No.1 for the day in Game, 1 minute ago.
Photo_user_blank_big
jimwallentine is ranked No.1 for the day in Game, 1 minute ago.
Photo_user_blank_big
jimwallentine is ranked No.1 for the day in Game, 2 minutes ago.
Photo_user_blank_big
jimwallentine is ranked No.1 for the day in Game, 2 minutes ago.
Photo_user_blank_big
jimwallentine is ranked No.1 for the day in Game, 2 minutes ago.