Joker’s Stash claims 3 million cards stolen from Dickey’s Barbecue

Joker’s Stash, one of the most notorious web forums for stolen credit card data, has claimed a new scalp. Sellers on the site this week claimed to be offering 3 million payment card numbers used at Dickey’s Barbecue Pit, a U.S. fast-food chain, researchers at intelligence firm Gemini Advisory said Thursday. More than 100 of the barbecue joint’s locations were affected by the breach, and the data is being sold for a median price of $17 per card, according to the research. The data from Dickey’s Barbecue Pit customers appears to have been compromised between July 2019 and August 2020, according to Gemini Advisory. Numerous restaurant and hospitality chains have been hit by scammers in recent years because of the personal financial data they collect. “Given the widespread nature of the breach, the exposure may be linked to a breach of the single central processor, which was leveraged by over a quarter of all […]

The post Joker’s Stash claims 3 million cards stolen from Dickey’s Barbecue appeared first on CyberScoop.

Continue reading Joker’s Stash claims 3 million cards stolen from Dickey’s Barbecue

Interesting Attack on the EMV Smartcard Payment Standard

It’s complicated, but it’s basically a man-in-the-middle attack that involves two smartphones. The first phone reads the actual smartcard, and then forwards the required information to a second phone. That second phone actually conducts the transaction on the POS terminal. That second phone is able to convince the POS terminal to conduct the transaction without requiring the normally required PIN.

From a news article:

The researchers were able to demonstrate that it is possible to exploit the vulnerability in practice, although it is a fairly complex process. They first developed an Android app and installed it on two NFC-enabled mobile phones. This allowed the two devices to read data from the credit card chip and exchange information with payment terminals. Incidentally, the researchers did not have to bypass any special security features in the Android operating system to install the app…

Continue reading Interesting Attack on the EMV Smartcard Payment Standard

Stripe adds card issuing, localized card networks and expanded approvals tool

At a time when more transactions than ever are happening online, payments behemoth Stripe is announcing three new features to continue expanding its reach. The company today announced that it will now offer card issuing services directly to businesses to let them in turn make credit cards for customers tailored to specific purposes. Alongside that, it’s going […] Continue reading Stripe adds card issuing, localized card networks and expanded approvals tool

44M Digital Wallet Items Exposed in Key Ring Cloud Misconfig

Millions of IDs, charge cards, loyalty cards, gift cards, medical marijuana ID cards and personal information was left exposed to the open internet. Continue reading 44M Digital Wallet Items Exposed in Key Ring Cloud Misconfig

Parking Meters That Were a Bit Too Smart for their Own Good

A common sight in automobile-congested cities such as New York are parking meters lining the curbs next to parking spots. They’re an autonomous way for the city to charge for the space taken by cars parked along the sidewalk near high-traffic commercial areas, incentivizing people to wrap up their business …read more

Continue reading Parking Meters That Were a Bit Too Smart for their Own Good

Mastercard jumps into the risk-assessment race with RiskRecon acquisition

Mastercard is getting into the security assessment business. The credit giant announced Monday it has agreed to acquire RiskRecon, a Salt Lake City-based startup that grades companies based on their ability to withstand cyberattacks and protect personally identifiable information. The companies did not disclose the terms of the deal. RiskRecon is one of several firms that collect publicly available data — such as what kind of web servers companies use and whether their protected information turns up on the dark web — to make cybersecurity assessments. Mastercard has an obvious financial interest in understanding which companies are more likely to be breached. CEO Ajay Banga has pushed for awareness that most data breaches start at small and medium-sized businesses (SMBs) and then spread to larger ones. Banga is a member of the Cyber Readiness Institute, a Washington nonprofit that distributes cybersecurity advice to SMBs. “Mastercard has been one of the brands that has stood out as a true innovator, focusing on the real problems of real business,” RiskRecon co-founder Kelly […]

The post Mastercard jumps into the risk-assessment race with RiskRecon acquisition appeared first on CyberScoop.

Continue reading Mastercard jumps into the risk-assessment race with RiskRecon acquisition

All Wawa Convenience Stores Infected with Credit Card-Stealing Malware

Malware was discovered in Wawa’s payment processing servers, and it’s believed that all convenience store locations were affected. The stolen information includes names and credit card numbers, among other data. Wawa CEO Chris Gheysens said… Continue reading All Wawa Convenience Stores Infected with Credit Card-Stealing Malware