ATM Thieves Swap Security Camera for Keyboard

This blog has featured stories about a vast array of impressive, high-tech devices used to steal money from automated teller machines (ATMs). But every so often thieves think up an innovation that makes all of the current ATM skimmers look like child’s play. Case in point: Authorities in Brazil have arrested a man who allegedly stole more than USD $41,000 from an ATM after swapping its security camera with a portable keyboard that let him hack the cash machine.

Photo: TV Bahia

The story comes from O Estado de S. Paulo (“The State of São Paulo“), a daily newspaper in Brazil’s largest city. According to the paper, late last month a crook approached an ATM at the Bank of Brazil and somehow removed the security camera from the machine. Apparently, the camera was a USB-based device, because the thief then was able to insert his own USB stick into the slot previously occupied by the camera. As you can imagine, a scene straight out of Terminator 2 ensued.

The attacker was then able to connect a folding keyboard to the ATM’s computer and restart the machine. The newspaper story isn’t crystal clear on the role of the USB device — whether it served as a replacement operating system or merely served to connect the keyboard to the machine (it’s not hard to imagine why this would be so easy, since most ATMs run on some version of Microsoft Windows, which automatically installs drivers for most USB-based input devices).

At any rate, after the thief rebooted the ATM’s computer, he was reportedly able to type the value of the currency notes that he intended to withdraw. According to the story, the thief started by removing all of the R $100 bills, and then moved on to the R $50 notes, and so on.

A crude skimming device removed from an Inova Hospital in Fairfax, Va. last month.

A crude skimming device removed from an Inova Hospital in Fairfax, Va. last month.

As clever as this hack was, the crook didn’t get away: The police were alerted by the central bank’s security team, and caught the thief in the process of withdrawing the funds. Brazilian authorities said they believe the man was being coached via phone, but that the guy they apprehended refused to give up the identity of his accomplice. My guess is the one coaching the thief had inside knowledge about how these machines operated, and perhaps even worked at a financial institution at one point.

These kinds of attacks make traditional ATM skimmer scams look positively prehistoric by comparison. But the sad part is that even really crude skimming devices can be very lucrative and go undetected for months. I was reminded of this last week, when, for the third time in as many months, authorities discovered ATM skimmers at hospitals within a few miles of here. Local police believe the same thieves are responsible for planting all of the fraud devices, which are relatively unsophisticated but nonetheless enabled the theft of thousands of dollars over a period of several weeks.

The front of the card-skimming device.

According to Fairfax County Police, one was discovered on the same ATM located near the lobby gift shop at Inova Fairfax Hospital on Tuesday, November 27. A hospital employee noticed that the input slot for the card was loose and wobbly; when she inserted her bank card, the device fell off.

A second device was discovered on a machine located in the Inova Fair Oaks Hospital lobby adjacent to the cafeteria on Wednesday, November 28 around 1 p.m. A hospital security guard discovered the device after being notified of the prior incident.

ATMs like this one, tucked away in a hallway corner, may be easier for thieves to compromise and keep compromised.

In September, Fairfax police recovered a remarkably similar skimmer from that very same ATM in front of the Fairfax hospital gift shop. I popped by the hospital today and snagged a picture of the cash machine in question (at left, and sadly, I did not discover another skimmer).

Interestingly, the police said that none of these bank machines are either owned or “monitored” by Inova staff; while they are are located on hospital property, the banking institutions that own them are responsible for their maintenance and management.

I doubt these skimmers would have gone undiscovered for weeks a time had they been attached to ATMs at actual bank branches. These incidents are a good reminder that, whenever possible, stick to ATMs located at bank branches. And, as always, keep a close eye on your bank statement for fraudulent charges.


Original news article at https://krebsonsecurity.com on December 05, 2012 at 03:05AM

AV-TEST removes its certification for Microsoft Security Essentials

(LiveHacking.Com) –  The latest set of tests performed by AV-TEST, an independent IT security and anti-virus research institute  has shown that Microsoft’s Security Essentials (MSE) can only detect 64 per cent of zero-day threats when running under Windows 7. This is down from 69 per cent in the previous round of certification tests, which were carried out […]


Original news article at https://www.livehacking.com on December 03, 2012 at 01:27PM

Get an Annual Subscription to Prey Pro for 72% Off and Protect Up to 10 Devices from Loss and Theft

Prey is one of our favorite ways to protect your devices against theft. If a laptop or mobile is lost or stolen, Prey can help you recover it. It’s free to use for up to three devices, but if you have a family with lots of devices to protect, or just a bunch of your own, you need Prey Pro. StackSocial currently has a deal that knocks 72% off a year’s worth of service so you can protect up to 10 devices for only $50. More »


Original news article at https://lifehacker.com on December 01, 2012 at 02:30AM

Maine Construction Company And Bank Settle Dispute Over $345,000 Online Banking Heist

A Maine construction company that sued its bank after losing $345,000 in an online banking heist has settled its dispute after a protracted legal battle that raised questions about the bank’s responsibility in protecting customer accounts against cyber fraud.

The settlement between Patco Construction and People’s United Bank (formerly Ocean Bank) comes about four months after the U.S. Court of Appeals for the First Circuit faulted the bank’s security measures at the time of the theft and advised the two sides to work out a compromise.

Click for complete article >>


Original news article at https://www.teamshatter.com on November 27, 2012 at 09:04PM

Samsung printers contain hidden, hard-coded management account

https://www.flickr.com/photos/samsungtomorrow/7641624576/

Samsung printers released before October 31, 2012, have been found to contain a hard-coded account that could allow an attacker to remotely take control of the device.

As described in a vulnerability note released by the US Computer Emergency Response Team (CERT), affected printers have a Simple Network Management Protocol (SNMP) account programmed into their firmware. This account continues to permit access to the device even if SNMP functions are disabled in the printer’s management utility. Some Dell printers manufactured by Samsung are also affected.


Original news article at https://news.hitb.org/ on November 27, 2012 at 06:28AM

Sysadmin creates tool to scour web for hacked data

https://cdn.i.haymarket.net.au/Utils/ImageResizer.ashx?n=https%3a%2f%2fi.haymarket.net.au%2fNews%2f20121122082338_OSINT+OPSEC+tool.JPG&w=220&c=1

A Wellington system administrator has developed a tool to identify corporate secrets, hacked data and even stolen credit cards as they emerge on social networks and online clipboards.

Users could set the OSINT OPSEC (Open Source Intelligence / Operational Security) Tool to monitor for keywords, allowing, for example, an organisation to be alerted if a hacking group dumped its sensitive data to clipboard site Pastebin.


Original news article at https://news.hitb.org/ on November 27, 2012 at 04:57AM