<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>(-) HatSecurity.com &#187; identify theft</title>
	<atom:link href="http://hatsecurity.com/tag/identify-theft/feed/" rel="self" type="application/rss+xml" />
	<link>http://hatsecurity.com</link>
	<description>../something for all Hats</description>
	<lastBuildDate>Thu, 30 Dec 2010 05:49:09 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>UK defense ministry in possible identify theft scare</title>
		<link>http://hatsecurity.com/2008/10/10/uk-defense-ministry-in-possible-identify-theft/</link>
		<comments>http://hatsecurity.com/2008/10/10/uk-defense-ministry-in-possible-identify-theft/#comments</comments>
		<pubDate>Fri, 10 Oct 2008 19:11:59 +0000</pubDate>
		<dc:creator>Tahir</dc:creator>
				<category><![CDATA[general]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[identify theft]]></category>

		<guid isPermaLink="false">http://hatsecurity.com/?p=184</guid>
		<description><![CDATA[CNN is reporting that the Ministry of Defense of the UK has lost track of a portable hard drive which according to a tabloid carries information on some 100,000 British military personnel and 600,000 potential recruits. One can only wonder whether the information on the hard drive was encrypted or not&#8230;]]></description>
			<content:encoded><![CDATA[<p>CNN is <a href="http://edition.cnn.com/2008/WORLD/europe/10/10/MOD.data.loss.ap/index.html" target="_blank">reporting</a> that the Ministry of Defense of the UK has lost track of a portable hard drive which according to a tabloid carries information on some 100,000 British military personnel and 600,000 potential recruits.</p>
<p>One can only wonder whether the information on the hard drive was encrypted or not&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://hatsecurity.com/2008/10/10/uk-defense-ministry-in-possible-identify-theft/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Biggest hacker underground market going bust; what next?</title>
		<link>http://hatsecurity.com/2008/09/21/darkmarket-biggest-hacker-underground-market-bust/</link>
		<comments>http://hatsecurity.com/2008/09/21/darkmarket-biggest-hacker-underground-market-bust/#comments</comments>
		<pubDate>Sun, 21 Sep 2008 12:35:05 +0000</pubDate>
		<dc:creator>Tahir</dc:creator>
				<category><![CDATA[general]]></category>
		<category><![CDATA[opinions]]></category>
		<category><![CDATA[identify theft]]></category>

		<guid isPermaLink="false">http://hatsecurity.com/?p=166</guid>
		<description><![CDATA[DarkMarket.ws, the online forum better known as the biggest hacker market for trading stolen online identities, credit card information, ATM skimmers, and a host of other related items &#8211; is shutting down Oct 4 according to a notice posted on the forum by one of the forum administrators, Splyntr. The shut down plan follows arrest [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://hatsecurity.com/wp-content/uploads/2008/09/darkmarket-ws.jpg"><img class="alignright size-full wp-image-168" style="margin: 3px;" title="darkmarket-ws" src="http://hatsecurity.com/wp-content/uploads/2008/09/darkmarket-ws.jpg" alt="" width="280" height="90" /></a>DarkMarket.ws, the online forum better known as the biggest hacker market for trading stolen online identities, credit card information, <a href="http://en.wikipedia.org/wiki/Credit_card_fraud#Skimming" target="_blank">ATM skimmers</a>, and a host of other related items &#8211; is shutting down Oct 4 according to a notice posted on the forum by one of the forum administrators, <em>Splyntr</em>.</p>
<p>The shut down plan follows <a href="http://www.haber7.com/haber/20080912/Enselenen-Chao-sanal-semayi-anlatti.php" target="_blank">arrest</a> of one of its administrators, <em>Cha0</em> (Cagatay Evyapan), by Turkish police earlier this month.</p>
<p>The whole story is covered in great detail this story on Wired&#8217;s Blog, <a href="http://blog.wired.com/27bstroke6/2008/09/notorious-crime.html" target="_blank">Threat Level</a>.  So, what&#8217; next after DarkMarket.ws?</p>
<p><span id="more-166"></span></p>
<p>DarkMarket emerged after ShadowCrew.com was taken offline and I reckon it is not going to take long before another online community fills the void left by DarkMarket&#8217;s departure from the scene.</p>
<p>There are already a handful of other established online forums that cater to the needs of cyber criminals and new ones crop up all the time offering some high-value loot for those in need:</p>
<div id="attachment_170" class="wp-caption aligncenter" style="width: 272px"><a href="http://hatsecurity.com/wp-content/uploads/2008/09/card_fraud_1.jpg"><img class="size-medium wp-image-170" title="card_fraud_1" src="http://hatsecurity.com/wp-content/uploads/2008/09/card_fraud_1-262x300.jpg" alt="Trade details by a &quot;respected&quot; underground individual on a new forum" width="262" height="300" /></a><p class="wp-caption-text">Fig. 1- A post on a DarkMarket wanna-be forum</p></div>
<div id="attachment_171" class="wp-caption aligncenter" style="width: 310px"><a href="http://hatsecurity.com/wp-content/uploads/2008/09/card_fraud_2.jpg"><img class="size-medium wp-image-171" title="card_fraud_2" src="http://hatsecurity.com/wp-content/uploads/2008/09/card_fraud_2-300x289.jpg" alt="dfs" width="300" height="289" /></a><p class="wp-caption-text">Fig. 2: Same post, more details</p></div>
<p>Some of the more established forums would welcome the extra traffic that they generate from the less experienced DarkMarket users, looking for other market places to trade in:</p>
<div id="attachment_173" class="wp-caption aligncenter" style="width: 310px"><a href="http://hatsecurity.com/wp-content/uploads/2008/09/fake_credit_card1.jpg"><img class="size-medium wp-image-173" title="fake_credit_card1" src="http://hatsecurity.com/wp-content/uploads/2008/09/fake_credit_card1-300x163.jpg" alt="asdsadsa" width="300" height="163" /></a><p class="wp-caption-text">Fig. 3: &quot;Real-looking&quot; credit cards packed with actual victim data are now being sold online. </p></div>
<div id="attachment_176" class="wp-caption aligncenter" style="width: 310px"><a href="http://hatsecurity.com/wp-content/uploads/2008/09/fake_credit_card2.jpg"><img class="size-medium wp-image-176" title="fake_credit_card2" src="http://hatsecurity.com/wp-content/uploads/2008/09/fake_credit_card2-300x165.jpg" alt="dsf" width="300" height="165" /></a><p class="wp-caption-text">Fig. 4: They sure do look &quot;real&quot;</p></div>
<p>Indepent trading sites are likely to see a surge in their business too as some of the cyber criminals are likely to deal direct without exposing any of their information on any online forums:</p>
<div id="attachment_175" class="wp-caption aligncenter" style="width: 233px"><a href="http://hatsecurity.com/wp-content/uploads/2008/09/dumps.jpg"><img class="size-medium wp-image-175" title="dumps" src="http://hatsecurity.com/wp-content/uploads/2008/09/dumps-223x300.jpg" alt="sdf" width="223" height="300" /></a><p class="wp-caption-text">Fig. 5: One of the more &quot;reputable&quot; stolen credit card sales website. </p></div>
<p>Although none of the existing online hacker market places can truly replace the stature of DarkMarket, there is likely to be a surge in competition amongst the various online underground sites to try and reach the level of popularity that DarkMarket currently enjoys.</p>
<p>Any new community formed by the existing DarkMarket admins is likely to see stricter membership controls which probably served as the weak link for the forum; DarkMarket user-level access accounts were being retailed at competing forums privately for US$800 and above, just a couple of weeks ago.</p>
<p>It would be interesting to see what comes next after DarkMarket &#8211; and how the law enforcement agencies play catch-up with the notorious underground hacker market places.</p>
]]></content:encoded>
			<wfw:commentRss>http://hatsecurity.com/2008/09/21/darkmarket-biggest-hacker-underground-market-bust/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Best Western Hotel group&#8217;s systems hacked</title>
		<link>http://hatsecurity.com/2008/08/24/best-western-hotel-group-hacked/</link>
		<comments>http://hatsecurity.com/2008/08/24/best-western-hotel-group-hacked/#comments</comments>
		<pubDate>Sun, 24 Aug 2008 13:51:49 +0000</pubDate>
		<dc:creator>Tahir</dc:creator>
				<category><![CDATA[general]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[identify theft]]></category>

		<guid isPermaLink="false">http://hatsecurity.com/?p=150</guid>
		<description><![CDATA[The Sunday Herald is reporting that an international gang of computer hackers has penetrated the booking system of the Best Western Hotel group and stolen the identities of an estimated 8 million hotel guests. The report states: A Sunday Herald investigation has discovered that late on Thursday night, a previously unknown Indian hacker successfully breached [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://hatsecurity.com/wp-content/uploads/2008/08/logo-bestwestern.gif"><img class="alignright size-full wp-image-151" title="logo-bestwestern" src="http://hatsecurity.com/wp-content/uploads/2008/08/logo-bestwestern.gif" alt="" width="97" height="89" /></a><a href="http://www.sundayherald.co.uk/news/heraldnews/display.var.2432225.0.0.php" target="_blank">The Sunday Herald</a> is reporting that an international gang of computer hackers has penetrated the booking system of the Best Western Hotel group and stolen the identities of an estimated 8 million hotel guests.</p>
<p>The <a href="http://www.sundayherald.co.uk/news/heraldnews/display.var.2432225.0.0.php" target="_blank">report</a> states:</p>
<blockquote><p>A Sunday Herald investigation has discovered that late on Thursday night, a previously unknown Indian hacker successfully breached the IT defences of the Best Western Hotel group&#8217;s online booking system and sold details of how to access it through an underground network operated by the Russian mafia.</p>
<p>It is a move that has been dubbed the greatest cyber-heist in world history. The attack scooped up the personal details of every single customer that has booked into one of Best Western&#8217;s 1312 continental hotels since 2007.</p></blockquote>
<p>Update (August 27 &#8211; 11PM +4GMT) &#8211; <a href="http://www.foxnews.com/story/0,2933,411403,00.html" target="_blank">FOX News is reporting</a> that Best Western has denied the extend of the hacking incident claiming <span id="intelliTXT">the report by the Sunday Herald as </span><span id="intelliTXT">&#8220;grossly unsubstantiated&#8221; and &#8220;largely erroneous.&#8221; </span></p>
<p>Best Western did, however, confirm that a hacker was able to penentrate its computer network in one of the hotels in Berlin and install a trojan on one of the computers designed to steal data.</p>
]]></content:encoded>
			<wfw:commentRss>http://hatsecurity.com/2008/08/24/best-western-hotel-group-hacked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Justice for largest hacking case ever</title>
		<link>http://hatsecurity.com/2008/08/06/justice-for-largest-hacking-case/</link>
		<comments>http://hatsecurity.com/2008/08/06/justice-for-largest-hacking-case/#comments</comments>
		<pubDate>Wed, 06 Aug 2008 08:53:55 +0000</pubDate>
		<dc:creator>Tahir</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[opinions]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[identify theft]]></category>

		<guid isPermaLink="false">http://hatsecurity.com/?p=106</guid>
		<description><![CDATA[CNN is reporting that 11 people were charged yesterday for allegedly stealing more than 40 million credit and debit card numbers. The hacking incidents relating to the accused took place at various major retail outlets in the USA over the past three years. The defendants come from U.S.; Estonia; Belarus; China, with one individual whose [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.cnn.com/2008/CRIME/08/05/card.fraud.charges/index.html" target="_blank">CNN</a> is reporting that 11 people were charged yesterday for allegedly stealing more than 40 million credit and debit card numbers. The hacking incidents relating to the accused took place at various major retail outlets in the USA over the past three years.</p>
<p>The defendants come from U.S.; Estonia; Belarus; China, with one individual whose country of origin still remains unknown.</p>
<p>From the <a href="http://www.cnn.com/2008/CRIME/08/05/card.fraud.charges/index.html" target="_blank">report:</a></p>
<blockquote><p>Under the indictments, three Miami, Florida, men &#8212; Albert &#8220;Segvec&#8221; Gonzalez, Christopher Scott and Damon Patrick Toey &#8212; are accused of hacking into the wireless computer networks of retailers including TJX Companies, whose stores include Marshall&#8217;s and T.J. Maxx, BJ&#8217;s Wholesale Club, OfficeMax, Barnes and Noble and Sports Authority, among others.</p>
<p>The three men installed &#8220;sniffer&#8221; programs designed to capture credit card numbers, passwords and account information as they moved through the retailers&#8217; card processing networks, said Michael Sullivan, the U.S. attorney in Boston.</p>
<p><span id="more-106"></span></p></blockquote>
<p>We can speculate a plenty about the poor security deployed at the major retail stores that were affected, but what intrigues me the most, is not that they had wireless network and let their <a href="http://hatsecurity.com/2008/07/28/rf-barrier-wardriving-protection/" target="_blank">RF waves propagate far and wide</a>, but that the affected stores did not learn from similar attacks that took place in the <a href="http://www.wi-fiplanet.com/columns/article.php/1142171" target="_blank">past. </a></p>
<p>Major card hacking rings today sell off the numbers to &#8220;wholesalers&#8221; who then go on to sell the numbers in the &#8220;retail market&#8221; by advertising the same on publicly available forums and IRC channels. A quick search on Google yields plenty of these postings:</p>
<div id="attachment_107" class="wp-caption aligncenter" style="width: 251px"><a href="http://hatsecurity.com/wp-content/uploads/2008/08/hacked_cards_1.jpg"><img class="size-medium wp-image-107" title="hacked_cards_1" src="http://hatsecurity.com/wp-content/uploads/2008/08/hacked_cards_1-241x300.jpg" alt="Hacked 1 " width="241" height="300" /></a><p class="wp-caption-text">Figure 1: Credit card nos. come cheap</p></div>
<div id="attachment_108" class="wp-caption aligncenter" style="width: 228px"><a href="http://hatsecurity.com/wp-content/uploads/2008/08/hacked_cards_2.jpg"><img class="size-medium wp-image-108" title="hacked_cards_2" src="http://hatsecurity.com/wp-content/uploads/2008/08/hacked_cards_2-218x300.jpg" alt="Hacked 2" width="218" height="300" /></a><p class="wp-caption-text">Figure 2: Global credit cards nos.</p></div>
<p>Although the law is catching up with the card rings, it would do us all good if the available security technologies are implemented effectively and people trained to ward off social engineers.</p>
]]></content:encoded>
			<wfw:commentRss>http://hatsecurity.com/2008/08/06/justice-for-largest-hacking-case/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Emirates Skywards accounts leaked on the net</title>
		<link>http://hatsecurity.com/2008/07/26/emirates-skywards-accounts-leaked-on-the-net/</link>
		<comments>http://hatsecurity.com/2008/07/26/emirates-skywards-accounts-leaked-on-the-net/#comments</comments>
		<pubDate>Sat, 26 Jul 2008 20:47:51 +0000</pubDate>
		<dc:creator>Tahir</dc:creator>
				<category><![CDATA[general]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[identify theft]]></category>

		<guid isPermaLink="false">http://hatsecurity.com/?p=55</guid>
		<description><![CDATA[It is not unusual to come across stolen identities on the web and this one is no exception. I came across a post in an underground forum listing a bunch of Emirates Skywards accounts. I picked a random account to verify the claims and the rest is pictured below: After going through the list, I [...]]]></description>
			<content:encoded><![CDATA[<p>It is not unusual to come across <a href="http://hatsecurity.com/2008/05/12/personal-details-of-over-7m-chileans-leaked/" target="_blank">stolen identities on the web</a> and this one is no exception. I came across a post in an underground forum listing a bunch of <a href="http://www.emirates.com">Emirates</a> Skywards accounts. I picked a random account to verify the claims and the rest is pictured below:</p>
<div id="attachment_57" class="wp-caption aligncenter" style="width: 310px"><a href="http://hatsecurity.com/wp-content/uploads/2008/07/sky1.jpg"><img class="size-medium wp-image-57" title="sky1" src="http://hatsecurity.com/wp-content/uploads/2008/07/sky1-300x182.jpg" alt="Skywards account main page" width="300" height="182" /></a><p class="wp-caption-text">Figure1: Skywards/Emirates account main page</p></div>
<div id="attachment_58" class="wp-caption aligncenter" style="width: 310px"><a href="http://hatsecurity.com/wp-content/uploads/2008/07/sky2.jpg"><img class="size-medium wp-image-58" title="sky2" src="http://hatsecurity.com/wp-content/uploads/2008/07/sky2-300x182.jpg" alt="Saved credit card information" width="300" height="182" /></a><p class="wp-caption-text">Figure 2: Saved credit card information</p></div>
<div id="attachment_56" class="wp-caption aligncenter" style="width: 310px"><a href="http://hatsecurity.com/wp-content/uploads/2008/07/sky3.jpg"><img class="size-medium wp-image-56" title="sky3" src="http://hatsecurity.com/wp-content/uploads/2008/07/sky3-300x182.jpg" alt="Skywards member personal information" width="300" height="182" /></a><p class="wp-caption-text">Figure 3: Skywards member personal information</p></div>
<p>After going through the list, I reckon the accounts were compromised as a result of <a href="http://www.owasp.org/index.php/Testing_for_Brute_Force" target="_blank">brute force attacks</a> given the relative serial order of the listed accounts, and the inadequate authentication controls available on emirates.com.</p>
<p>Skywards members &#8211; update your passwords now!<span id="more-55"></span></p>
<p><strong>Update</strong> (July 31,8:30 AM +4GMT): Emirates Airlines has acted swiftly to this threat and have added additional security measures on Emirates.com and Skywards.com websites:</p>
<div id="attachment_85" class="wp-caption aligncenter" style="width: 310px"><a href="http://hatsecurity.com/wp-content/uploads/2008/07/emirates-com-new-security-measures21.jpg"><img class="size-medium wp-image-85" title="emirates-com-new-security-measures21" src="http://hatsecurity.com/wp-content/uploads/2008/07/emirates-com-new-security-measures21-300x219.jpg" alt="Updated Skywards.com" width="300" height="219" /></a><p class="wp-caption-text">Figure 4: Updated Skywards.com login page</p></div>
<div id="attachment_86" class="wp-caption aligncenter" style="width: 275px"><a href="http://hatsecurity.com/wp-content/uploads/2008/07/emirates-com-new-security-measures1.jpg"><img class="size-medium wp-image-86" title="emirates-com-new-security-measures1" src="http://hatsecurity.com/wp-content/uploads/2008/07/emirates-com-new-security-measures1-265x300.jpg" alt="Updated Emirates.com" width="265" height="300" /></a><p class="wp-caption-text">Figure 5: Updated Emirates.com login page</p></div>
<p>A date of birth field is now required for authentication on both Emirates.com and Skywards.com websites. Additionally, client-side validation has been implemented (can&#8217;t confirm if this was available earlier though) that checks for valid Skywards membership number format.</p>
<p>A job well done &#8211; just what you would expect from a world-class airline!</p>
]]></content:encoded>
			<wfw:commentRss>http://hatsecurity.com/2008/07/26/emirates-skywards-accounts-leaked-on-the-net/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>

