Sony has issued yet another update on the PSN situation, following the security compromise which saw the network being taken offline nearly two weeks ago.
You might recall on Friday there was some speculation on parts of the net that underground forums had alleged credit card details stolen off PSN for sale. Indeed, one report suggested that Sony itself had been offered the chance to buy back the database.
Although it’s true that the source in question was less than convinced that the supposed hackers weren’t pulling their leg and making this whole story up.
However, Sony has clarified that it hasn’t been offered the chance to purchase such a list.
On the EU PlayStation blog, Nick Caplin, Head of Communications at SCEE, wrote: “One report indicated that a group tried to sell millions of credit card numbers back to Sony. To my knowledge there is no truth to this report of a list, or that Sony was offered an opportunity to purchase the list.”
Furthermore, in a clarifying mode, Sony also went on to make a point about the passwords which were pinched off PSN.
It had previously said that these weren’t encrypted and left it at that. However, they were subject to a cryptographic hash function – in other words, they weren’t just stored in cleartext form.
We found it hard to believe that they would have been, but given Sony’s lack of any clarification regarding the passwords, everyone was rather left in the dark as to exactly what security was maintained.
Of course, that doesn’t mean your password is safe by any means. Sony notes: “When the PlayStation Network and Qriocity services are fully restored, we strongly recommend that you log on and change your password.”
When PSN comes back online later this week, when users log on a forced system update will ensure they change their password.
But Sony also reminds: “Additionally, if you use your PlayStation Network or Qriocity user name or password for other unrelated services or accounts, we strongly recommend that you change them, as well.”
By Darren Allen
http://www.techwatch.co.uk
Sony denies hackers attempted to sell back credit card database
Credit Card Fraud Data Worth 50p
Credit card information and personal details are being traded for less than the cost of a can of cola, according to a new study.
IT security firm Symantec's latest annual security threat report revealed that criminals are buying people's card details, name, address and date of birth for just 50p.
With this information, fraudsters are able to commit identity fraud and scam large amounts of money from the cards.
Symantec chief scientist Guy Bunker warned that "there are signs of a price war developing, as online criminals find it increasingly easy to steal private details, and barter to sell them for bargain prices".
He added: "As above ground the world economy spirals, the underground economy has never been healthier."
According to UK payments association Apacs, card fraud losses reached £609.9m in 2008.
Transactions which do not require chip and pin protection - such as online payments - were the main drivers of growth in card fraud, Apacs claimed.
http://www.compareandsave.com/
Warning over telephone credit card fraud
TERIES have been warned to be on the alert after fraudsters conned £400 out of a Hawick pensioner.
The lady, who does not wish to be named, was duped into revealing her credit card details over the phone after being told she had won a holiday. The caller said they were from credit card giants Mastercard and that the holiday was a reward for prompt payment of her bills.
Her daughter told the Hawick News: "My mum kept telling them on the phone that she didn't think this was right, but they passed her onto three different people, including a supposed executive and they persuaded her to give over her details. They just made her feel that it was true and real."
The elderly lady was told the so-called "free" holiday would cost between £270 and £280, but when the credit card was subsequently contacted, the £400 sum had been lifted.
Her daughter added: "It's all in the hands of the credit card company now and they're treating it as fraud. My mum was lucky because she hasn't a big credit limit, but I'd hate to think of this kind of thing happening to other people."
By Gavin Gibbon
Update: Hatfield family's Christmas joy hit by credit card fraud
A MUM-OF-FIVE is warning people to be on their guard after she became the victim of card fraud just a week before Christmas.
Michelle Denty, from Hatfield, had stopped at a petrol station on Wednesday morning to use a cash machine.
And to her horror, she found £250 had been removed from her account.
Mrs Denty told the WHT what happened next.
"I immediately rang Nationwide," she said.
"They told me the money was taken out at 6.30am in Harlow, but I was sorting the children out at home then."
The 27-year-old was told it appeared her cashcard had been cloned, but she cannot recall a time when this could have happened.
She added: "I am normally very vigilant when I go to the cash machine and I always shield my PIN."
Mrs Denty, of The Downs, described the fraud as "upsetting" and said it had put a "major dampener" on her festive preparations.
"My husband is on the minimum wage, so we rely on tax credits to help us pay the bills," she said.
"We are on a very limited budget now for Christmas.
"The children now won't be able to have the extras I would hope to have been able to give them."
She also gave the following advice: "Be very vigilant and on your guard when using a cash machine."
Nationwide Building Society would not comment about Mrs Denty's individual case, but a spokeswoman said: "Where suspected fraudulent activity has taken place, Nationwide will investigate the case fully and refund all account holders who have been innocent victims of fraud.
Two charged in credit card theft may be part of larger fraud ring
ROSEVILLE -- Police have charged two Detroit men for trying to buy more than $2,000 in goods with a stolen credit card, officials said today.
Police believe Reshaun Keith Palmer, 29, and Will Deshawn Lynn, 27 are part of a larger identity theft and credit card fraud ring and continue to investigate, Deputy Police Chief James Berlin said.
Palmer was charged with receiving and concealing stolen property, a four-year felony, and conspiracy to commit credit card fraud, also a four-year felony, Berlin said.
Lynn was charged with credit card fraud, possession of stolen credit card, a four-year felony, and identity theft, also a four-year felony, officials said.
Police arrested Palmer and Lynn at about 8 p.m. Friday after the two suspects tried to buy $2,000 in merchandise from the Meijer store at 13 Mile and Little Mack.
The men were using a fake driver's license and a stolen American Express credit card, police said.
At the time of the attempted purchase, the suspects became suspicious when a store employee delayed the transaction to enable police officers to arrive.
The suspects fled and were spotted in a vehicle traveling westbound on Interstate 94.
Police stopped the vehicle, were able to determine the occupants were the suspects they sought and arrested them. Police also recovered about $3,500 in merchandise purchased fraudulently from other retailers, Berlin said.
You can reach Charles E. Ramirez at (586) 468-2905 or cramirez@detnews.com.
Charles E. Ramirez / The Detroit News
Careful what you click for
Beware when buying in Internet sales boom
By Alex Davis
alexdavis@courier-journal.com
There are 10 people on Fadden Holden's holiday shopping list this year, but don't look for the 28-year-old in any of the local malls.
With the same technique he uses for weddings and other special occasions, the east Louisville resident plans to buy his gifts on eBay, where he expects to find deals on sports memorabilia, magazine subscriptions and more.
"I've been using online shopping for a long time now," said Holden, who will soon graduate from the University of Louisville with a master's degree in mathematics. "It reduces your search costs."
A growing number of shoppers are getting that same idea -- even as a recent Better Business Bureau survey found that six in 10 of those who buy online acknowledge being anxious that their credit card information might be stolen during a transaction.
"Fears over the use and safety of personal information, including credit card numbers, telephone numbers, and home and e-mail addresses, are the main reasons online shoppers second-guess their decisions when making online purchases," said Charlie Mattingly, president of the BBB serving Louisville, Southern Indiana and Western Kentucky.
Yet, online holiday spending in November topped $10.7 billion through Monday, a 17 percent gain from a year ago, according to comScore, which tracks online consumer trends.
And that number is expected to get a big boost Dec. 10 -- that's Green Monday, which falls on the second Monday of December, and is considered the last safe day to ensure shipping by Christmas.
That's "when people spend the most amount of money online," said Jamie Diamond, a spokesman for Symantec, the San Francisco company responsible for Norton Antivirus computer software.
In all, nearly three-fourths of Americans with Internet access will do at least some of their holiday shopping online this year, according to a recent poll from Zogby Interactive. And online marketing consultant Forrester Research estimates holiday shopping sales on the Internet will rise 20 percent this year.
UPS, which has its main air hub in Louisville, measures the rise in online shopping by counting the number of customers who track shipments by visiting UPS.com.
In 1995, 100,000 users checked the status of freight that way. This year, UPS expects 150 million inquiries during the peak the week before Christmas, said company spokesman Mike Mangeot.
Cautious with credit
Experts caution that fears about credit card theft are justified, whether you are shopping online or at the store.
But the credit industry has taken broad steps to combat the theft of consumer information in recent years.
For example, American Express, Discover, Mastercard Int'l and Visa last month approved standards that soon will prohibit any software handling credit or debit card data from storing transaction information -- including personal identification numbers, or names and bank data saved to a card's magnetic stripe.
Such measures are promulgated by Boston's PCI Security Standards Council, a private company formed by all the major credit card companies in late 2006.
Instead of each company setting Internet security and store security rules on its own with vendors, PCI acts as a clearinghouse for security standards accepted by the major credit providers.
"The whole reason for us being (here) is so we can set standards that can protect consumer or payment card data," said PCI spokesman Glenn Boyet.
On the law enforcement side, Internet auction fraud prompts nearly half of all complaints to the Internet Crime Complaint Center or IC3, a partnership between the Federal Bureau of Investigation and the National White Collar Crime Center.
The BBB advises that shoppers protect themselves before buying by checking out the reliability ratings or the BBB rating of any online seller.
CyberSource, which provides retailers electronic payment services, says the fraud rate is holding steady at about 1.4 percent of all online sales.
But consumers should use the same care in shopping online that they would take at malls or other venues, said Reanna Smith-Hamblin, spokeswoman for the BBB in Louisville. That means guarding personal information and researching the company's background, she said.
"Shop with people you know," she said. "If it sounds too good to be true, it probably is."
Taking the online leap
Online retailers say that while shoppers might say they are nervous about Internet crime, it's clear that a growing number are willing to set such concerns aside and punch their credit card account numbers into Web sites.
"There's a growing amount of trust within online retail," said Marc Cowlin, spokesman for CafePress.com, a California company that employs about 300 people at its warehouse in Louisville.
Cindy Mann, 42, of Simpsonville, said she expects to spend about $3,000 on holiday gifts this year -- about 85 percent of that online.
She said she takes precautions -- for example, using only her American Express card because it offers theft protections. And she said she "wouldn't dare ever" use a debit card because that has information about her bank account.
With security tools improving regularly, responsible companies can build a strong reputation with customers, said Cowlin, whose company allows users to design and personalize their own merchandise, such as T-shirts and coffee mugs.
Even so, some shoppers remain shy about opening their wallets online, even if they're savvy with a computer.
For example, Tracey Goff, 37, an educational consultant from Elizabethtown who was shopping Friday at Oxmoor Center, said she never buys online -- partly because of safety concerns but also because, "I like to see it, feel it, touch it."
But Meagan Deeley, 22, of Mount Washington, said that while she works at Von Maur, she expects to do half of her holiday shopping online this year. "It's a big benefit because you don't have to be out in traffic," she said, adding that she relies on her computer's Norton antivirus protection and always checks a Web site's reliability rating.
And Maurice Rhodes, a 20-year-old package handler who lives in Louisville, said he routinely buys such things as Air Jordan shoes on eBay.
"I never worry about security," he said, "I just do it."
Meanwhile, sitting outside a coffee shop near her home in the Highlands, Amanda Baerwalde said she plans to do all of her holiday shopping at small businesses in her neighborhood -- but not out of any great concern about security.
She goes online to buy airplane and concert tickets but said that for other goods, she'd rather walk a couple of blocks and buy in person.
"When everything's so concentrated," she said, "I don't see the point of looking elsewhere for it."
Reporter Alex Davis can be reached at (502) 582-4644. Reporter Jere Downs contributed to this story.
Few ID thefts from Web
Secret Service files show 10% of cases were from Internet
By Peter J. Sampson
A review of Secret Service files has found that half of the cases of identity theft involved technological devices, such as computers, scanners and digital cameras, and only 10 percent were done exclusively through the Internet.
In 20 percent of the other cases, thieves stole personal data the old-fashioned way.
Low-tech tactics included rerouting mail by sending change-of-address requests to institutions handling credit-card and bank accounts, swiping items right from mailboxes, and "Dumpster diving" -- going through trash for personal information that can be used to produce counterfeit documents and to open credit accounts.
Researchers from Utica College's Center for Identity Management and Information Protection in New York analyzed 517 Secret Service cases of ID theft from 2000 to 2006. It was the first study of closed files from the federal agency, which is responsible for investigating identity theft and fraud.
Among their findings:
• A fifth of the time, identity thieves stole personal data at their workplace. Of them, 60 percent were employed in the retail industry -- stores, car dealerships, gas stations, casinos, restaurants, hotels, hospitals and doctors' offices. Another 22 percent worked for financial services, such as banks and credit-card companies, and 9 percent were in government.
• People were victimized by a family member or friend 16 percent of the time.
• Personal information was stolen from someone's home, car, wallet or pocketbook 12 percent of the time.
• Most of the thefts occurred in the Northeast and the South.
• The median loss was just over $31,000, although in one case a thief spent millions on luxury vehicles and established shell companies to defraud more victims.
The study confirms a recent Consumer Reports poll that found Americans overwhelmingly believe they are more vulnerable to identity theft when a business has their Social Security number. Most respondents said they want companies to stop using the numbers to identify customers.
A Social Security number, coupled with your date of birth and address, is the Holy Grail for identity thieves, said Cindy Wofford, special agent in charge of the Secret Service's field office in Newark, N.J.
"In addition to shredding documents before discarding them, Wofford recommends not storing any passwords on your computer's hard drive. Hackers know how to retrieve them, she said.
Consumers have become more knowledgeable about Internet scams that try to trick them into divulging account numbers, passwords and other personal information.
Doug Bem, an inspector for the U.S. Postal Service, said residents should not use their home mailboxes for outgoing mail. And by no means should they raise the flag on the box if they do.
"That's as much an indicator to a thief, as it would be to a letter carrier, that there's mail to be had," he said.
To prevent fraudulent rerouting of mail, Bem said, the Postal Service uses a dual verification procedure in which confirmation letters are sent to both the old and new addresses to verify the request is legitimate before any mail is forwarded.
In the Federal Trade Commission's 2003 survey of identity theft victims, 4 percent indicated stolen mail was the source of their problems, he noted.
Peter J. Sampson writes for The Record in Hackensack, N.J.
Recalls, returns can be avoided
Experts say shoppers should find out about products before buying
Sheryl Harris, The New York Times
Most years, it may be better to give than receive, but this year, it's a wash.
It's hard to pick just the right toy when you realize that 25 million have been recalled because they can maim, poison or reduce the SAT-scoring potential of our kids.
What with tainted toys, gift certificate snags, tough return policies and restocking fees, the joy of giving could lose just a bit of its seasonal sparkle.
Luckily, consumer groups have stepped in with some well-timed advice on what to avoid as you shop while the dollar drops.
Toys
Avoid metal jewelry, especially cheap metal jewelry, for young children, most groups say. If metal jewelry is inexpensive, looks like silver and seems heavy for its size, it may contain lead, warns the New York attorney general's office.
Don't buy toys unless they're age appropriate. Age labels on the box don't relate to a child's intellect but are based on his or her developmental stage. A toy suitable for one age group can be frustrating or dangerous for a younger child.
Avoid toys with magnets that can come loose. Many kids hold toys in their mouths, and if they swallow magnets it can result in life-threatening intestinal blockages and tears. If you do give kids magnetic toys, make sure the magnets can't be tugged loose.
Avoid toys from vending machines as well as toys that don't carry brand names, says Consumer Reports. (It's true that well-known brands have been recalled this year, but at least they're easy to identify, and name manufacturers often have a mechanism for exchanging toys.)
Although lead has grabbed most of the headlines, choking is the leading cause of death for children under 4. Any toy small enough to slide through a toilet-paper tube is a choking hazard for a young child. Avoid small toys for children under 3 -- as well as for any older child who still mouths toys.
If you bought presents early, make sure you check toys, art supplies and children's metal jewelry against the growing list of children's items recalled this year. For links to recalls, visit cleveland.com/business.
Privacy
Remove credit cards, Social Security cards and other unneeded documents from your wallet before you head to the mall, says Privacy Rights Clearinghouse. Pickpockets are busy this time of year. Never leave your purse or a jacket containing your wallet or cell phone in a shopping basket. Men should carry wallets in a front pants pocket, which makes them harder to steal.
Read an online retailer's privacy policy before you buy. The Privacy Rights Clearinghouse recommends you patronize online retailers who have agreed to voluntary privacy guidelines through organizations like TRUSTe (www.truste.org), Verisign (www.verisign.com) or BBBonline (www.bbb.online.org). Clicking on the icon should lead you to the icon-issuer's Web site so you can verify.
Never shop online unless you make sure the Web site encrypts account and personal information it collects. Privacy Rights Clearinghouse says to look for "https://" in the URL address or the closed padlock icon to make sure the page is secure. (An open lock indicates it's probably not secure.) Some browsers have color-coded indicators when you click on an encrypted page.
Make sure merchants print no more than five digits of your credit card number on your receipt. By law, electronically printed receipts can't carry your entire number on the customer copy.
Report violators to the Federal Trade Commission at www.ftc.gov.
Buying
Avoid using a debit or check card to pay for purchases. Most debit cards don't carry the consumer protections that credit cards do, and exorbitant overdraft fees can pile up before a consumer realizes what's happening, says the Privacy Rights Clearinghouse.
Not only that, the group warns, some crooks use "skimming" devices to steal card information from merchant card-swipers. A debit card can give them direct access to your bank account.
Using a credit card for purchases provides the best consumer protection because it allows you to dispute a purchase if merchandise isn't as advertised or if there's a billing error. It's the safest way to shop online and the best way to purchase big-ticket items.
Avoid overspending. If you're worried you'll go over your budget if you use plastic, draw up a gift list with price caps and stick to it. You also may want to stash away the cash to pay off your card after each shopping trip. (Technically, paying off a charge lessens your ability to dispute, so you may want to bank the saved money until the presents are opened and you're sure they're as advertised.)
Ignore rebate offers when you're considering whether to buy.
Rebates can be notoriously hard to collect. Ask yourself if you'd buy the item at that price if you couldn't get the advertised rebate. If the answer is no, keep shopping.
Don't forget to ask for gift receipts. It can be difficult to return an item for the purchase price without the gift receipt, advises Consumer World, a Web site for consumers.
Ask before you buy
Check the store's return policy before you buy anything. In some states, retailers can set any return policy they'd like -- including not allowing them -- as long as they post the policy in a conspicuous place.
Check the performance and reliability of appliances and electronics through Consumer Reports or unbiased product reviews before you buy.
Check the reliability of retailers you're not familiar with through the Better Business Bureau (www.bbb.org).
Ask if there are restocking fees on returned products. They may be hard to dodge on electronics, but some retailers slap them on furniture and other goods. Ask whether people who return items are tracked. Privacy Rights Clearinghouse says that, in an effort to combat organized retail fraud, some retailers collect information about consumers who return items and share the data with a central clearinghouse.
Combating online credit card fraud
http://money.ninemsn.com.au
One of the risks for merchants when it comes to selling goods and services online is credit card fraud. Basically, you are almost operating in a vacuum and you have no idea whether your online customers are trustworthy. Considering you will not actually see your online customers, there are two things you know about them:
1. They want to buy something from you and;
2. They want to use their credit card.
The next question is how do you know that your customer is not a child with his/her mother's credit card or a thief with a stolen credit card? You don't and that is why it is a good idea to identify suspicious customer behaviour. Just as you would watch a suspicious character in your offline premises, it is also important to be aware of the tell-tale signs of credit card fraud.
There are fundamentally two credit card fraud types:
* The smash and grab where the number of fraudulent acts is small, sometimes just a one-off, but the product value may be high.
* The "drip effect" where the number of acts is large and the value small.
According to the Worldwide E-commerce Fraud Prevention Network, an international survey highlighted online fraud as a significant problem. However, 70 percent of the respondents believed fraud prevention tools could keep it to a minimum.
Fraud reduction tools
The four most popular fraud reduction tools being used have been identified as:
1. Address verification systems (70 percent)
2. Customer follow-ups (54 percent)
3. Real-time authorisations (54 percent)
4. Post-process fraud management (43 percent).
According to the Worldwide E-commerce Fraud Prevention Network, an international survey highlighted online fraud as a major stumbling block.
However, when they were asked to list the most effective reduction methods the survey members put address verification systems in top place followed by real-time authorisations.
Almost 50 percent of online merchants surveyed said fraud had cost their business between $1000 to $10,000. Nineteen per cent reported costs at more than $100,000.
And almost 60 percent of merchants said they spent less than one per cent of total revenues on fraud prevention.
When it comes to credit card fraud, it is important to remember:
* Merchants are usually the victims of credit card fraud. It is rarely the customers.
* The card owner has a limited liability. Most of the liability rests with the merchant.
* You need good anti-fraud procedures in place to protect you and your customers.
For useful links to fraud information and prevention tips, see the Merchant Fraud Squad (www.merchantfraudsquad.com) or visit www.antifraud.com.
Fraud warning signs
There are a number of suspicious behaviours which can help highlight a potentially fraudulent act. Knowing what to look for is important. Consider the following:
* Watch out for large orders placed without regard to size, colour, style or price of stock.
* If an international customer demands a speedy delivery without regard to freight and delivery or transport costs, beware. Many international customers will opt for the cheapest method of transportation to keep costs down.
* A first-time customer who makes a very large order and wants it shipped over night should be treated with caution.
* Be wary of customers who always use free e-mail accounts as their reply e-mail addresses. Suspicious customers may use many of these types of accounts. Just proceed with caution until the customers establish themselves as being trustworthy.
* It may be wise to not fully trust customers who won't allow you to call them and insists on calling you or communicating entirely through e-mail.
* A common form of credit card fraud is a child using a parent's credit card. Just be cautious, especially if you get a large order for teenage-type products.
* If you get a number of orders on the same day from the same customer for large quantities of products it is best to make sure it is not someone using someone else's credit card.
* Research has also shown that stores that sell computer equipment, stereos and televisions are the most likely targets for credit card fraud as the goods can easily be resold.
When you sign up for a credit card, you sign up for arbitration
Would you agree to let someone arbitrate your dispute with a credit card company if you knew he or she almost always decided in favor of the company?
Thousands of consumers do that every day when they sign up for a credit card, says Public Citizen, a national consumer group.
Buried in the fine print is an implied agreement to submit any dispute to binding arbitration. That means you can’t go to court and have a jury decide your case.
Instead, you have to accept an arbitrator that the company chooses — and in many cases pays for.
Reviewing data made public in California, the study found that a major arbitration firm, the National Arbitration Forum, ruled against consumers 95 percent of the time.
The study, which reviewed 19,000 of 34,000 cases involving credit card and collections disputes, supports two bills in Congress that propose changes to ensure consumers are treated fairly.
“The results of mandatory arbitration demonstrate a stunning bias against consumers,” said Laura MacCleery, director of Public Citizen’s Congress Watch Division. “These are agreements buried in the fine print most people don’t even know they are consenting to.”
Business officials, however, dispute the findings, contending that they more reflect a bias toward the trial attorney lobby.
“The plaintiffs’ lawyers’ attempt to undermine the arbitration system is not about justice for consumers, it is about growing the size of their own pocketbook,” said Lisa A. Rickard, president of the U.S. Chamber Institute for Legal Reform.
The American Banking Association said the Public Citizen study fails to say “that arbitration is one of the fairest, most efficient methods for resolving complex disputes between consumers and businesses of all kinds, including lenders.” The ABA said the report varies wildly from previous reports.
In fact, industry-supported studies have found that more than half of respondents find arbitration a faster and more efficient forum for resolving disputes.
But the Public Citizen study is one of the first to focus extensively on mandatory binding arbitration. And while it looked only at credit card cases, it has broad implications because binding arbitration is embedded in many consumer contracts covering everything from cell phones to cars.
For its part, the National Arbitration Forum issued a statement saying: “Consumer outcomes in arbitration are the same as in court.” It also said: “Judges review arbitration awards to make sure they are fair.”
But Mitch Stoddard, a St. Louis lawyer who has had cases before the National Arbitration Forum., disputes that.
It’s hard to appeal or get a court review, he said, mainly because the consumer has already agreed to be bound by a finding. “It really comes down to what role we want the law to play in protecting consumer rights,” said Stoddard, noting that the forums are not bound by traditional rules of evidence.
Even so, there is a valid argument that arbitration, when handled fairly, can be more efficient than going to court.
One problem, though, is that a potential conflict of interest exists when the companies that choose the arbitrators also finance their salaries, said Johnson County real estate lawyer Max Gordon.
But consumers have no way of knowing in advance whether the process is fair because it is cloaked in secrecy.
Indeed, the Public Citizen study is unique because it reviewed data only recently made public in California, which remains the only state that allows public disclosure of arbitration statistics.
Even industry sources agree that binding arbitration should be made more transparent. They say some arbitrators follow consumer protection guidelines. But some don’t.
Michael Geigerman, managing director of United States Arbitration and Mediation Midwest Inc., said consumers should be assured that their arbitrator is neutral. “One question you’d want to ask is, ‘How many cases have you arbitrated for a company, and what were your decisions in those cases,’ ” he said.
Right now, only the companies can know that — putting consumers at a disadvantage.
Paul Wenske's In Your Corner columns appear Sunday in The Star's MoneyWise section. To reach him, write in care of the business desk at 1729 Grand Blvd., Kansas City, MO 4108, call (816) 234-4454 or send e-mail to pwenske@kcstar.com.
Hackers steal credit card numbers and billing addresses of Ticketmaster customers in Germany free RSS feed from Security Park
Hackers have stolen credit card numbers and billing addresses of 66,000 customers who purchased tickets with a credit card from the Kartenhaus.de website between October 2006 and September 2007. Kartenhaus is based in Hamburg and sells a wide range of tickets for shows throughout Germany as well as artist merchandise, music and videos.
Ticketmaster, the parent company, advised customers to "check your credit card bills as soon as possible to identify any irregularities or abuse".
Paul Davie, founder of Secerno, commented "It is even unlikely that the sort of authentication and encryption solutions required by PCI compliance would have done anything to stop this breach. This just goes to prove the importance of proactive security and predefined policies that can understand the normal behaviour of those accessing the database, and allow intelligent anomaly protection. New technologies exist to enable this and should be adopted without delay."
http://www.securitypark.co.uk
Can I have your money please?
Warning worth reading.. I, personally have encountered the first type but not the second one. Whatever it is, be very careful when it comes to your credit card. Alternatively, never entertain all those sales’ cold calls from telemarketers.. (Sorry folks, for those of you in the sales/marketing line)
Credit Card Scam No. 1
I received a call from a company that said they are representing VISA.
They will ask you are you using any visa card, from which bank. Then they said they will send you a Service Card, a new promotion from Visa which is TOTALLY FREE. That card include a free one year insurance cover from AIA RM100,000.
You can enjoy discount from many many of their outlets, then they ask me for the credit card number for verification and they want to make sure my card is still a valid Visa Card. I refuse to give them the card number cos I know that the last 3 digits of our card is actually like our pin number. They keep asking the number and giving me a lot of reason they need to verify my card.
Then I ask that girl who call me their office number, 03-22732600. I said that I am busy right now and I’ll call her back later. Before the conversation end, she told me again that the service card is totally free for whole life, but we need to pay rm499 for the processing fee, ask me not to misunderstand.
Just after I hang up the call, I call back to the phone number that she give me, I ask the receptionist
“What is your company name?” Then she start asking me why I call? She ask me did I agree with the rm499 fee and when I said No, she said “then you don’t need to know our company name!”
It is a SCAM! I already called to my bank to report the incident. Hope that all of you won’t be trapped in this kind Of SCAM.
Credit Card Scam No. 2
Note, the callers do not ask for your card number; THEY already have it. This information is worth reading. By understanding how the VISA & MasterCard Telephone Credit Card Scam works, you’ll be better prepared to protect yourself.
What the scammers want is the 3-digit PIN number on the back of the card. Don’t give it to them. Instead, tell them you’ll call VISA or Master card directly for verification of their conversation.
My husband was called on Wednesday from “VISA”, and I was called on Thursday from “MasterCard”.
The scam works like this: Person calling says, “This is (name), and I’m calling from the Security and Fraud Department at VISA. My Badge Number is 12460 your card has been flagged for an unusual purchase pattern, and I’m calling to verify. This would be on your VISA card which was issued by (name of bank). Did you purchase an Anti-Telemarketing Device for $497.99 from a Marketing company based in Arizona?”
When you say “No”, the caller continues with, “Then we will be issuing a credit to your account. This is a company we have been watching and the charges range from $297 to $497 just under the $500 purchase pattern that flags most cards. Before your next statement, the credit will be sent to (gives you your address), is that correct?”
You say “yes”. The caller continues - “I will be starting a Fraud investigation. If you have any questions, you should call the 1- 800 number listed on the back of your card (1-800-VISA) and ask for Security. You will need to refer to this Control Number. The caller then gives you a 6 digit number. “Do you need me to read it again?”
Here’s the IMPORTANT part on how the scam works. The caller then says, “I need to verify you are in possession of your card “. He’ll ask you to “turn your card over and look for some numbers”. There are 7 numbers; the first 4 are part of your card number, the next 3 are the security Numbers that verify you are the possessor of the card. These are the numbers you sometimes use to make Internet purchases to prove you have the card. The caller will ask you to read the 3 numbers to him.
After you tell the caller the 3 numbers, he’ll say, “That! is correct, I just needed to verify that the card has not been lost or stolen, and that you still have your card. Do you have any other questions?” After you say No, the caller then thanks you and states, “Don’t hesitate to call back if you do”, and hangs up.
You actually say very little, and they never ask for or tell you the card number. But after we were called on Wednesday, we called back within 20 minutes to ask a question. Are we glad we did! The REAL VISA Security Department told us it was a scam and in the last 15 minutes a new purchase of $497.99 was charged to our card. Long story made short – we made a real fraud report and closed the VISA account. VISA is reissuing us a new number. What the scammers want is the 3-digit PIN number on the back of the card. Don’t give it to them. Instead, tell them you’ll call VISA or Master card directly for verification of their conversation.
The real VISA told us that they will n! ever ask for anything on the card as they already know the! information since they issued the card! If you give the scammers your 3 Digit PIN Number, you think you’re receiving a credit. However, by the time you get your statement you’ll see charges for purchases you didn’t make, and by then it’s almost to late and/or more difficult to actually file a fraud report.
What makes this more remarkable is that on Thursday, I got a call from a “Jason Richardson of MasterCard” with a word-for-word repeat of the VISA scam. This time I didn’t let him finish. I hung up! We filed a Police report, as instructed by VISA. The police said they are taking several of these reports daily! They also urged us to tell everybody we know that this scam is happening.
http://www.malaysiandaily.com/
Cardholder Advice
To help protect yourself from becoming a victim of card fraud, APACS suggests you follow these top tips:
* Guard your card and card details.
* Don't let your card out of your sight when making a transaction.
* Ask the retailer to confirm the amount being debited from your card.
* Carefully discard your receipts from card transactions. Shred all your receipts and documents that contain information relating to your financial affairs.
* Check your receipts against your statements carefully. If you find an unfamiliar transaction contact your bank or building society immediately.
* Never write down your personal identification number (PIN) and never disclose it to anyone, even if they claim to be from your bank, building society or the police.
* When using a cash machine, be wary of anyone who might be trying to watch you enter your PIN and do not allow yourself to be distracted by anyone or anything.
* Don't keep your chequebook with your cards.
* Report lost or stolen cards or suspected fraudulent use of your card account to your bank or building society immediately. The 24-hour emergency number is on your last statement, or call directory enquiries for the number.
Other important tips
* Sign any new cards as soon as they arrive.
* Cut expired cards through the magnetic stripe and/or chip when replacement cards arrive.
* Pay attention to card expiry dates. If your replacement card hasn't arrived call your bank or building society to check the status of the new card.
* Don't leave your cards unattended in a bag, briefcase or jacket pocket in a public place and keep your bag or briefcase on your lap.
If you are a victim of card fraud
* Inform your bank or building society immediately.
* Report the theft or loss to the police immediately. This can be inconvenient and time consuming but it will simplify the process of getting your bank or building society to refund the losses from any unauthorised use of your card.
If someone else uses your card before you tell your bank or building society that it has been lost or stolen, or before you tell them that someone else knows your PIN, the most you will have to pay is £50. In practice the bank or building society will usually refund the full amount lost, but if you are shown to have acted fraudulently or without reasonable care, for example by keeping your PIN written down with your card, you may have to meet all the losses.
http://www.apacs.org.uk
Types of card fraud
Lost and stolen card fraud — a card is physically stolen from your wallet or home, or it is lost, and is then used by a criminal, posing as you, to obtain goods and services. Most fraud of this type takes place before you have reported the loss.
This type of card fraud has remained fairly static for the past five years, but a decrease is expected once chip and PIN is fully rolled out in the UK.
Counterfeit card fraud (also known as Skimming) — a counterfeit, cloned or skimmed card is one that has been printed, embossed or encoded without permission from the card company, or one that has been validly issued and then altered or recoded.
Most cases of counterfeit fraud involve skimming, a process where the genuine data on a card's magnetic stripe is electronically copied onto another card, without the legitimate cardholder's knowledge.
Skimming can occur at retail outlets — particularly bars, restaurants and petrol stations — where a corrupt employee puts your card through a device, without your knowledge, that electronically copies the data from your card's magnetic stripe. Sometimes skimming takes place at cash machines where tampering has occurred and a skimming device has been fitted. The information is usually then sold on higher up the criminal ladder where counterfeit cards are made.
Often you will be unaware of such fraud until your statement arrives, showing purchases that you did not make.
Card-not-present (CNP) fraud — this includes fraud conducted over the Internet, by telephone, fax and mail order. It is perpetrated when criminals obtain card details through the theft of your card details. It is now the largest type of card fraud in the UK.
The problem in countering this type of fraud lies in the fact that neither the card nor the cardholder is present at a till point in a shop.
Mail non-receipt card fraud — this type of fraud involves your card being stolen in transit, once it has been sent out to you from your bank or building society. At particular risk for this type of fraud are properties with communal letterboxes, such as flats and student halls of residence.
http://www.apacs.org.uk
Plastic Card Fraud
Cards are always safer than cash. The chances of you becoming a victim of card fraud are still low (fraudulent transactions make up 0.141% of all transactions). If you are unlucky enough to be a victim you will not suffer any financial loss as a consequence providing you have not acted fraudulently or without reasonable care.
Criminals are always looking for ways to get hold of your cards, but the banking industry is committed to fighting the fraudster on all fronts. Chip and PIN is a vital tool to help us further protect cards and we continue to work on a raft of other initiatives.
You can best protect yourself by always looking after your cards and card details, checking your statement to ensure you have not been a victim, disposing of receipts with care and NEVER disclosing your PIN even if somebody claims to be from your bank or the police.
Card Watch is a UK banking industry initiative that aims to raise awareness of card fraud prevention. For comprehensive information on fraud - including the types, levels and what is being done to combat it - visit the Card Watch website at www.cardwatch.org.uk
http://www.apacs.org.uk/
Massive credit card heist suspected
Over 140,000 transactions run through tiny Net firm
A Los Angeles-based Internet company said that 140,000 fake credit card charges, worth $5.07 each, were processed through its transaction system Thursday, in a computer scam that may have affected as many as 25 companies. The apparent fraud suggests that a computer criminal may have obtained a sizable list of stolen credit card numbers and was testing them for validity, credit card fraud expert Dan Clements said.
Paul Hynek, CEO of Web site operator Spitfire Novelties, said its credit card transaction processor, Online Data Corp, approved some 62,000 of the apparently false charges, valued at over $300,000.
Hynek said Online Data representatives revealed to him Friday morning that about 25 of the payment processor’s other e-commerce customers had suffered similar problems Thursday.
But Online Data president John Rante said late Friday that he was “not sure” that any other e-commerce sites were hacked.
The false charges started showing up at Spitfire’s TalkingTP.com Web site at 1 p.m. PT Thursday, Hynek said, but the company didn’t realize what was happening until early evening. By Friday morning, credit card holders who had noticed fraudulent charges on their accounts were peppering Spitfire with questions.
“The phone was ringing every 20 or 30 seconds ... with people asking ‘who the hell are you,’” said Russ Colby, Spitfire’s president. Spitfire, a small e-commerce company that generates five to 30 transactions a day, suddenly was deluged with credit card authorizations.
“There wasn’t a system in place to say, ‘you’ve generated 140,000 charges, that’s more than your normal volume,’” Hynek said.
Online Data is a reseller of Verisign Inc. credit card payment gateway services, according to Verisign spokesperson Janine Dunne, who declined to say how many merchants were impacted by the apparent fraud, but did indicate Spitfire wasn’t the only company hit.
While Verisign actually performed the authorizations, Dunne blamed the reseller, Online Data, for the incident. She said the company issued poor passwords to its customers.
“We encourage resellers to assign strong passwords. The issue here appears to be the nature of passwords assigned to merchants,” she said.
But Rante said the merchant was to blame for not changing its password often enough.
“All of us need to change our passwords,” Rante said. “We issue a starter password just like most companies do. We strongly urge the merchant to go in and change their password. This merchant failed to change their password and they were hacked.
Hynek told MSNBC.com the merchant password issued to him by Online Data was “OnlneAp16501.” He said he thought the alphabetic part of that password stands for “Online app,” which might be easy for a hacker to guess.
Darrell Bethune was one of many victims who noticed the $5.07 charge Friday while checking his credit card statement online.
“I live in Canada and haven’t been to Los Angeles in years,” he said.
While some $300,000 in charges were approved by Verisign’s systems, the firm actually halted the transactions before they were “settled,” meaning the $316,000 was never actually credited to Spitfire’s merchant account. In fact, the criminals were probably only testing the cards to see if they were valid.
Running cards through the authorization process is worthwhile to criminals, because they now have some 60,000 valid cards to sell on the black market, according to Clements, a credit card fraud expert who operates CardCops.com.
About 80,000 of the cards run throughout Spitfire’s systems were declined, Hynek said, meaning more than half the stolen cards were outdated or had already been canceled.
This is not the first time credit card thieves have used hacked online merchant accounts to test cards. In April, MSNBC.com reported that thieves were using “brute force” methods to test thousands of card numbers through hacked Authorize.net merchant accounts, posting tiny 5 and 10-cent charges. In one such incident, 13,000 pre-authorizations attempts were made in a single weekend.
It’s not clear how many apparently stolen cards were run through the 25 other Online Data merchants that Hynek said were also compromised.
Also unclear is what happens next. Apparently, word of the 62,000 valid stolen cards hadn’t filtered down to credit card issuers yet. When Bethune spotted the false charge, he called his credit card bank, Wells Fargo, and asked to have his card canceled. The bank hadn’t yet heard about the alleged heist.
“It’s not clear what responsibility Verisign has right now,” said Clements. “The credit card companies would sure be interested in that list ... these are cards that are clearly targeted for fraud.”
Dunne said Verisign had alerted credit card companies about the compromised cards, but declined to provide further details.
By Bob Sullivan
Technology correspondent
MSNBC
Tips to help you avoid credit card fraud
- Don't carry credit cards you don't use and never leave them unattended in a purse, briefcase or wallet.
- Always make sure you get your credit card receipt because it just may include your credit card number. Never toss it in a public trash bin. You'll need that receipt later anyway to tally things up when your statement arrives.
- Shred all documents that might include your credit card number before disposing of them - old slips, credit card statements, bills, anything.
- Never give your number over the phone to someone that you do not know. It's OK if you initiate the call but if you get a call at home from anyone that you do not know by name do not give them your credit card number.
- Never respond to an e-mail asking for your number, no matter how official or legitimate it looks. These bogus e-mails are the #1 fraud right now on the Internet.
- Review your monthly statement as soon as it comes and report any problems right away. To insure your rights, follow-up by filing a written complaint form.
- If using a bank card where you have the option to use credit or debit, ALWAYS USE THE CREDIT OPTION as this may prevent the skimmer device from accessing your four digit pin number.
Types of Fraud
Stolen Card Fraud
When a card holder loses or has their credit card stolen, it is possible for the thief to make unauthorized purchases on that card up until the card is cancelled. Businesses that accept credit cards are not permitted to request supplemental ID from the cardholder, unless the credit card is not signed. A thief can potentially purchase thousands of dollars in merchandise or services before the card holder or the bank realize that the card is in the wrong hands. Self-serve payment systems such as gas stations are also highly prone to accepting a stolen credit card, as there is no verification of the card holder's identity, however many stations are trying to prevent this by adding a check requiring the user to key in a zip code. The zip code must match the code registered to the credit card or the transfer will fail.
Account Takeover Fraud
Fraud perpetrators call in and impersonate actual cardholders using stolen personal information. They have the address and other information of the cardholder changed to an address they control. Additional cards and possibly PIN mailers are requested and issued to the new address and used by the fraudsters to make purchases and/or obtain cash advances.
Sometimes the fraudster will attempt to add themselves or an alias that they control as an authorized user to the account in order to make it easier to commit the fraud.
Credit Card Mail Order Fraud
Using a stolen credit card number, or computer generated card number, a thief will order stolen goods.
Skimming
Skimming is the theft of credit card information by a dishonest employee of a legitimate merchant, manually copying down numbers, or using a magnetic stripe reader on a pocket-sized electronic device. Common scenarios for skimming are restaurants or bars where the skimmer has possession of the victim's credit card out of their immediate view. The skimmer will typically use a small keypad to unobtrusively transcribe the 3 or 4 digit Card Security Code which is not present on the magnetic strip.
Many instances of skimming have been reported where the perpetrator has put a device over the card slot of a public cash machine ( Automatic Teller Machine ), which reads the magnetic strip as the user unknowingly passes their card through it. These devices are often used in conjunction with a pin-hole camera to read the user's pin number at the same time.
To prevent Cards in countries such as the UK are issued featuring a smart chip with public key encryption. The chip cannot be copied, but the card number, expiry date and security code can be, and this set of data is often sufficient to use the victim's credit card account for fraudulent purposes with so-called "card not present" transactions, e.g., manual input, over the telephone or internet.
Carding
Carding is a term used by fraudsters for a process they use to verify that sets of stolen credit card data are still valid. The fraudsters will present each set of credit card details in turn on a website that has real-time transaction processing, making a purchase for a very small monetary amount so as not to use up the card's credit limit, and so as not to attract the attention of a human reviewer to the transaction.
Often, an online donation site for a charity is used instead of an eCommerce merchant, since there is no need to find an item of a suitable price to put in the virtual shopping cart, nor to supply shipping details. The carder may do this manually with a web browser, or may write automated software to interface to the website's checkout or billing forms.
In the past, carders used to use computer programs called "generators" to produce a sequence of credit card numbers, and then test them to see which were valid accounts. However, this process is no longer viable due to widespread requirement by internet credit card processing systems for additional data such as the billing address, the 3 to 4 digit Card Security Code, and/or the card's expiry date. Nowadays, carding is more typically used to verify credit card data obtained directly from the victims by Skimming and Phishing.
A set of credit card details that has been verified in this way is known in fraud circles as a phish. A carder will typically sell data files of phish to other individuals who will carry out the actual fraud. Market price for a phish ranges from US$1.00 to US$50.00 depending on the type of card, freshness of the data and credit status of the victim.
Credit Card Fraud: 21 Tips to Protect Yourself
Although credit card fraud is certainly on the rise -- and credit card fraud on the Internet is rising even more dramatically -- many savvy Internet shoppers know that the reality is that it's actually much safer to enter your credit card number on a secure online order form than it is to give your credit card to a waiter at a restaurant.
After all, what's to stop the waiter from writing down your credit card number and placing orders on the phone with it later?
And research shows that the rate of fraudulent purchases made by cell phones is much higher than credit card fraud on the Net.
Nevertheless, we encourage you to take precautions when giving out any confidential information (including your credit card number) over the Internet, over the phone... or anywhere else for that matter!
Always use common sense -- it is the best rule of thumb.
Nonetheless, we've created 21 tips to protect yourself from credit card fraud -- which you'll find below.
First though, we wanted to mention a much more prevalent -- and much less publicized -- aspect of credit card fraud: the dangers of credit card fraud for businesses who accept credit cards over the Net.
Internet ScamBusters' 21 Credit Card Fraud Prevention Tips:
1. Keep an eye on your credit card every time you use it, and make sure you get it back as quickly as possible. Try not to let your credit card out of your sight whenever possible.
2. Be very careful to whom you give your credit card. Don't give out your account number over the phone unless you initiate the call and you know the company is reputable. Never give your credit card info out when you receive a phone call. (For example, if you're told there has been a 'computer problem' and the caller needs you to verify information.) Legitimate companies don't call you to ask for a credit card number over the phone.
3. Never respond to emails that request you provide your credit card info via email -- and don't ever respond to emails that ask you to go to a website to verify personal (and credit card) information. These are called 'phishing' scams.
4. Never provide your credit card information on a website that is not a secure site.
5. Sign your credit cards as soon as you receive them.
6. Shred all credit card applications you receive.
7. Don't write your PIN number on your credit card -- or have it anywhere near your credit card (in the event that your wallet gets stolen).
8. Never leave your credit cards or receipts lying around.
9. Shield your credit card number so that others around you can't copy it or capture it on a cell phone or other camera.
10. Keep a list in a secure place with all of your account numbers and expiration dates, as well as the phone number and address of each bank that has issued you a credit card. Keep this list updated each time you get a new credit card.
11. Only carry around credit cards that you absolutely need. Don't carry around extra credit cards that you rarely use.
12. Open credit card bills promptly and make sure there are no bogus charges. Treat your credit card bill like your checking account -- reconcile it monthly. Save your receipts so you can compare them with your monthly bills.
13. If you find any charges that you don't have a receipt for -- or that you don't recognize -- report these charges promptly (and in writing) to the credit card issuer.
14. Always void and destroy incorrect receipts.
15. Shred anything with your credit card number written on it.
16. Never sign a blank credit card receipt. Carefully draw a line through blank portions of the receipt where additional charges could be fraudulently added.
17. Carbon paper is rarely used these days, but if there is a carbon that is used in a credit card transaction, destroy it immediately.
18. Never write your credit card account number in a public place (such as on a postcard or so that it shows through the envelope payment window).
19. Ideally, it's a good idea to carry your credit cards separately from your wallet -- perhaps in a zippered compartment or a small pouch.
20. Never lend a credit card to anyone else.
21. If you move, notify your credit card issuers in advance of your change of address.
If you suspect credit card fraud:
If your credit cards are lost or stolen, contact the issuer(s) immediately.
Most credit card companies have toll-free numbers and 24-hour service to deal with these emergencies -- they are eager to avoid credit card fraud.
According to US law, once you have reported the loss or theft of your credit card, you have no more responsibility for unauthorized charges. Further, your maximum liability under federal US law is $50 per credit card -- and many credit card issuers will even waive that fee for good customers.
If you follow all these tips, it will go a long way in protecting you from credit card fraud.
Credit to original author:
Internet ScamBusters™
By Audri and Jim Lanford
Copyright © Audri and Jim Lanford.
All rights reserved.
Issue #79 June 9, 2004
Introduction.
Over forty million dollars. Somewhere around 900,000 victims across 22 countries. The biggest credit card fraud ever. Fraudulent credit card transactions generated using adult web site merchant accounts.
A fascinating story, but not as new as one would think. Since this web site was first created in December of 1998, when I learned I'd had 6 months worth of fraudulent transactions on a business Visa card, I've learned that this type of fraud has been going on for years. Criminal merchant account holders collude with shady banks and transaction processors -- it's an old story that predates the Internet.
What's new is the ability to run this scam across the entire world, and to attack hundreds of thousands of victims in a very short period of time. The Internet has given an old scam new legs. It has exposed the smoldering weaknesses in our credit card processing system.
This site is dedicated to chronicling this fraud, and to focusing attention on important weaknesses in our banking, credit card, and e-commerce systems. Although I focus on the particular scam I was victimized by, the information here will be of interest to anyone who has been victimized by similar frauds or who wants to see e-commerce succeed.J K Publications (alias Webtel, Netfill, etc) ran a sizeable fraud, somewhere in the range of 40-50 million dollars, distributed across about 900,000 credit cards in small recurrent charges ($20 US). JK Publications' front companies generated about a third of all customer complaints at one major credit card company in late 1998. Their merchant accounts had a 'chargeback' rate 100 times the national average; each time a merchant account was closed by the credit card companies, they opened a new one. In late 1998 they alone accounted for 4% of all Visa chargebacks.
The JK Publications fraud operated under a number of business names. Court filings by the US Federal Trade Commission refer to 3 principals. Prior to the filings, from Dec 4-20, 1998 I and many contributors working togother over the Net, identified front companies involved in this operation. We also identified an individual, Ken Taves, (KT) who appeared to be active in all of the front companies, and a few others besides. Since that time KT has been named in a public inditement by the Federal Trade Commission (FTC). His career is described in more detail in two LA Times articles, this fraud has been well covered in the August 1999 issue of Scientific American.
J K Publications was aided in this fraud by the actions of Charter Pacific Bank (San Fernando Valley, California, see InterNic entry and more below). According to an LA Times story reporting on FTC investigations (Jeff Leeds, 9/11/99) CP Bank sold Ken Taves about 900,000 (90%) "of the credit card numbers that he allegedly used to run up $45.7 million in mostly bogus charges against consumers worldwide". [12] CP Bank also held J K Publications various merchant accounts, and kept them operating even as complaints mounted.
Apparently the bank made millions processing credit card transactions for adult industries. In addition to numbers harvested from the adult entertainment business, they also sold numbers from the two-third of the bank's 250 merchant accounts belonging to other merchant accounts including mail-order firms and retailers.
In addition to persons who'd used their credit cards online (some who'd used them to buy adult materials, most who had not), victims included persons who'd never used their credit card anywhere!
Leeds' article also confirmed one of the main allegations of this page -- that banks and processors often accept transactions that lack key identifiers, such as expiration dates and card holder name. The credit card number alone will suffice for small transactions.
A few sad lessons have been learned during this investigation. The banks who manage the credit cards have treated many of the victims fairly poorly. The processors who manage transactions do not have the technology for even trivial validation of transactions. There are some pretty crooked banks out there. Prosecution for this type of fraud is rare. Visa/MasterCharge, who have the ultimate authority, are not coordinating anti-fraud activities and are not providing the technology for a better transaction system. Existing credit card anti-fraud sanctions move extremely slowly, allowing a company to generate fraudulent transactions for at least a year.
credits to original author: http://www.faughnan.com/ccfraud.html