{"id":4166,"date":"2016-08-12T08:59:39","date_gmt":"2016-08-12T03:29:39","guid":{"rendered":"https:\/\/www.qadit.com\/blog\/?p=4166"},"modified":"2016-08-12T08:59:39","modified_gmt":"2016-08-12T03:29:39","slug":"this-atm-hack-allows-crooks-to-steal-money-from-chip-and-pin-cards","status":"publish","type":"post","link":"https:\/\/qadit.com\/blog\/this-atm-hack-allows-crooks-to-steal-money-from-chip-and-pin-cards\/","title":{"rendered":"This ATM Hack Allows Crooks to Steal Money From Chip-and-Pin Cards"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/ift.tt\/2an9TGf\" title=\"This ATM Hack Allows Crooks to Steal Money From Chip-and-Pin Cards\"><\/p>\n<div>\n<div dir=\"ltr\">\n<p>\nForget about security! It turns out that the Chip-and-PIN cards are just as easy to clone as magnetic stripe cards.\n<\/p>\n<p>\nIt took researchers just a simple chip and pin hack to withdraw up to $50,000 in cash from an ATM in America in under 15 minutes.\n<\/p>\n<p>\nWe have been told that EMV (<\/p>\n<p><i>Europay, MasterCard and Visa<\/i><\/p>\n<p>) chip-equipped cards provides an extra layer of security which makes these cards more secure and harder to clone than the old magnetic stripe cards.\n<\/p>\n<p>\nBut, it turns out to be just a myth.\n<\/p>\n<p>\nA team of security engineers from Rapid7 at Black Hat USA 2016 conference in Las Vegas demonstrated how a small and simple modifications to equipment would be enough for attackers to bypass the Chip-and-PIN protections and enable unauthorized transactions.\n<\/p>\n<p>\nThe demonstration was part of their presentation titled, <\/p>\n<p><i>&#8220;Hacking Next-Gen ATMs: From Capture to Washout,&#8221; <\/i><\/p>\n<p>[<\/p>\n<p><a href=\"https:\/\/ift.tt\/2aFNOyA\" rel=\"nofollow\" target=\"_blank\">PDF<\/a><\/p>\n<p>]. The team of researchers was able to show the audience an ATM spitting out hundreds of dollars in cash.<\/p>\n<h3>\nHere&#8217;s How the Hack Work<\/h3>\n<p>\nThe hack requires two processes to be performed.\n<\/p>\n<p>\nFirst, the criminals need to add a small device known as a <\/p>\n<p><b>Shimmer <\/b><\/p>\n<p>to a point-of-sale (POS) machine (here, ATM&#8217;s card reader) in order to pull off a man-in-the-middle (MITM) attack against an ATM.\n<\/p>\n<p>\nThe shimmer sits between the victim&#8217;s chip and the card reader in the ATM and can record the data on the chip, including PIN, as the ATM reads it. It then transmits this data to the criminals.\n<\/p>\n<p>\nThe criminals then use a smartphone to download this stolen data and recreate the victim&#8217;s card in an ATM, instructing it to eject cash constantly.\n<\/p>\n<p>\nTod Beardsley, a security research manager for Rapid7, <\/p>\n<p><a href=\"https:\/\/ift.tt\/2aXac8w\" rel=\"nofollow\" target=\"_blank\">told<\/a><\/p>\n<p> the BBC that shimmer is basically a tiny RaspBerry-Pi-powered device that could be installed quickly to the outside of the ATM without access to the internals of the cash machine.\n<\/p>\n<blockquote class=\"tr_bq\"><p>\n&#8220;It&#8217;s really just a card that is capable of impersonating a chip,&#8221; Beardsley said. &#8220;It&#8217;s not cloning.&#8221;<\/p><\/blockquote>\n<p>\nThe perpetrators would only be able to replicate each card for a few minutes and use it to fraudulently withdraw money, enabling them to make between up to $50,000, but Beardsley suggests that a network of hacked chip-and-pin machines could create a constant stream of victims.\n<\/p>\n<p>\nResearchers have disclosed full details about the issue in Chip-and-PIN ATMs to banks and major ATM manufacturers and said they hope the institutions (currently unnamed) are examining the issue.<\/p>\n<\/div>\n<\/div>\n<p>via https:\/\/ift.tt\/2azMWAP<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Forget about security! It turns out that the Chip-and-PIN cards are just as easy to clone as magnetic stripe cards. It took researchers just a simple chip and pin hack to withdraw up to $50,000 in cash from an ATM in America in under 15 minutes. We have been told that EMV ( Europay, MasterCard &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/qadit.com\/blog\/this-atm-hack-allows-crooks-to-steal-money-from-chip-and-pin-cards\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;This ATM Hack Allows Crooks to Steal Money From Chip-and-Pin Cards&#8221;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false},"version":2}},"categories":[12],"tags":[],"class_list":["post-4166","post","type-post","status-publish","format-standard","hentry","category-itsec"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p9AH7Q-15c","_links":{"self":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts\/4166","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/comments?post=4166"}],"version-history":[{"count":1,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts\/4166\/revisions"}],"predecessor-version":[{"id":4167,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts\/4166\/revisions\/4167"}],"wp:attachment":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/media?parent=4166"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/categories?post=4166"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/tags?post=4166"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}