Skip to main content

Exclusive: Cybercrime firm says uncovers six active attacks on U.S. merchants

A cybercrime firm says it has uncovered at least six ongoing attacks at U.S. merchants whose credit card processing systems are infected with the same type of malicious software used to steal data from Target Corp.

Andrew Komarov, chief executive of the cybersecurity firm IntelCrawler, told Reuters that his company has alerted law enforcement, Visa Inc and intelligence teams at several large banks about the findings. He said payment card data was stolen in the attacks, though he didn't know how much.

IntelCrawler's findings are the latest sign that the cyberattacks disclosed by Target Inc and upscale department store Neiman Marcus are part of a wider assault on U.S. retailer customer data security.

On Thursday, the U.S. government and the private security intelligence firm iSIGHT Partners warned merchants and financial services firms that the BlackPOS software used against No. 3 U.S. retailer Target had been used in a string of other breaches at retailers - but did not say how many or identify the victims.

Credit card companies, banks and retailers say that victims of any fraud resulting from the theft of their payment card data bear "zero liability" and will be credited for fraudulent purchases made on their accounts.

"Our rules say five days, but most consumers get (their money) back within 24 hours," Visa spokeswoman Rosetta Jones said.

Yet consumer advocates said that any debit card fraud could result in money being drained from a bank, mutual fund or other cash account at a time when those funds were really needed.

"Even if you are able to recover the money later, that's going to cause you an awful lot of pain and heartburn," said Jamie Court, president of Consumer Watchdog, a nonprofit advocacy group.

Data breaches can also be costly for the retailers and credit card firms affected, along with the companies that process the payments, people who have reviewed past attacks say.

LATEST ATTACKS

Komarov, an expert on cybercrime who has helped law enforcement investigate previous attacks, told Reuters on Friday that retailers in California and New York were among those compromised by BlackPOS. Reuters was unable to confirm their names.

Komarov said he has not directly contacted those merchants. Security experts typically report cybercrimes through law enforcement rather than going directly to victims because the process can be time-consuming and victims are often suspicious when they first learn of attacks.

BlackPOS was developed by a hacker whose nickname is "Ree4" and who is now about 17 years old and living in St. Petersburg, Russia, according to Los Angeles-based IntelCrawler.

The teenager sold the malicious software to cybercriminals who then launched attacks on merchants, said Komarov, who has been monitoring Ree4's activities since March.

Komarov declined to specifically identify the sources of his intelligence, though he said he has been monitoring criminal forums where Ree4 sells his software and posted an excerpt of a chat with a client on the IntelCrawler website.

Officials with the Russian Interior Ministry could not be reached for comment when Reuters attempted to contact them after office hours on Friday.

_0">

The bulk of the attacks have occurred in the United States, but about 30 percent have occurred in other countries, including Australia and Canada, Komarov said.

_1">

Target last month disclosed the theft of some 40 million payment card numbers in a breach uncovered over the holiday shopping season, and later reported that 70 million customers' records had also been taken.

_2">

Neiman Marcus last week said that it too was victim of a cyberattack. Sources have told Reuters that at least three other well-known national retailers have been attacked.

_3">

John Watters, chief executive of iSIGHT Partners, which is helping the U.S. Secret Service with its investigation into the attacks, said that he expects the pace of assaults on merchants to pick up.

_4">

Copycats will pile on, using similar software, which can be purchased on underground forums, and similar techniques to launch attacks on retailers, he said. "They are saying: 'This is a great idea.'"

_5">

BlackPOS is a type of RAM scraper, or memory-parsing software, which enables cybercriminals to grab encrypted data by capturing it when it travels through the live memory of a computer, where it appears in plain text.

_6">

It is derived from code that has been floating around underground cybercrime forums since at least 2005 and may be related to malicious software used in attacks as early as 2003, said Shane Shook, an executive with cybersecurity firm Cylance Inc who has helped investigate major breaches at retailers.

_7">

While the technology has been around for many years, its use has increased as retailers have improved their security, making it more difficult for hackers to obtain credit card data using other approaches.

_8">

It succeeded in evading detection by anti-virus software when it infected the Windows-based point-of-sales terminals at retailers like Target, according to the report that the government privately distributed to merchants on Thursday, which iSIGHT Partners helped prepare.

_9">

Officials with the Secret Service could not immediately be reached for comment.

_10">

(Additional reporting by Richard Valdmanis, Lisa Baertlein, Mark Hosenball, David Henry and Megan Davis; Editing by Richard Valdmanis, Chizu Nomiyama and Jonathan Oatis)

_11">

Popular posts from this blog

Study Abroad USA, College of Charleston, Popular Courses, Alumni

Thinking for Study Abroad USA. School of Charleston, the wonderful grounds is situated in the actual middle of a verifiable city - Charleston. Get snatched up by the wonderful and customary engineering, beautiful pathways, or look at the advanced steel and glass building which houses the School of Business. The grounds additionally gives students simple admittance to a few major tech organizations like Amazon's CreateSpace, Google, TwitPic, and so on. The school offers students nearby as well as off-grounds convenience going from completely outfitted home lobbies to memorable homes. It is prepared to offer different types of assistance and facilities like clubs, associations, sporting exercises, support administrations, etc. To put it plainly, the school grounds is rising with energy and there will never be a dull second for students at the College of Charleston. Concentrate on Abroad USA is improving and remunerating for your future. The energetic grounds likewise houses various

Best MBA Online Colleges in the USA

“Opportunities never open, instead we create them for us”. Beginning with this amazing saying, let’s unbox today’s knowledge. Love Business and marketing? Want to make a high-paid career in business administration? Well, if yes, then mate, we have got you something amazing to do!   We all imagine an effortless future with a cozy house and a laptop. Well, well! You can make this happen. Today, with this guide, we will be exploring some of the top-notch online MBA universities and institutes in the USA. Let’s get started! Why learn Online MBA from the USA? Access to More Options This online era has given a second chance to children who want to reflect on their careers while managing their hectic schedules. In this, the internet has played a very crucial in rejuvenating schools, institutes, and colleges to give the best education to students across the globe. Graduating with Less Debt Regular classes from high reputed institutes often charge heavy tuition fees. However onl

Sickening moment maskless 'Karen' COUGHS in the face of grocery store customer, then claims she doesn't have to wear a mask because she 'isn't sick'

A woman was captured on camera following a customer through a supermarket as she coughs on her after claiming she does not need a mask because she is not sick.  Video of the incident, which has garnered hundreds of thousands of views on Twitter alone, allegedly took place in a Su per Saver in Lincoln, Nebraska according to Twitter user @davenewworld_2. In it, an unidentified woman was captured dramatically coughing as she smiles saying 'Excuse me! I'm coming through' in the direction of the customer recording her. Scroll down for video An unidentified woman was captured dramatically coughing as she smiles saying 'Excuse me! I'm coming through' in the direction of a woman recording her A woman was captured on camera following a customer as she coughs on her in a supermarket without a mask on claiming she does not need one because she is not sick @chaiteabugz #karen #covid #karens #karensgonewild #karensalert #masks we were just wearing a mask at the store. ¿ o