Latest news
Luckily for them, there's an alternative: selling the information to other crooks that are more adept at bleeding bank accounts dry and are ready to take the risk for doing it - end everybody wins.
Webroot's Dancho Danchev has recently uncovered a seemingly well-established outfit for selling stolen card information - so much so that the crook behind the scheme has set up a professional-looking e-shop.
The shop is advertised on a number of carding forums, and the crook can be contacted only via ICQ.
The page itself looks great: a good - and apparently changeable - design, and a shop whose functionality does not seem to differ much from any other legitimate one - shopping cart and all (click on the screenshot to enlarge it):

The e-shop also has a helpful search engine so that the customers can find exactly what they need.
"The service is currently offering 9,132 stolen credit cards for sale, and has already managed to sell 3292 credit cards to prospective cybercriminals," Danchev says, and points out that the going rate for a sample stolen credit card depends on whether the card is debit or credit. The former go for $16, and the latter for $30 per item, but there are also discounts to be had for bulk purchases.
For those of you wondering why the owner of this shop would sell credit card data for $30 a pop when he can probably extract ten or twenty times as much from the compromised accounts, the answer is risk forwarding.
"Instead of manually verifying the balance of the cards, he’s focused on bulk orders and forwarding the risk of getting caught to the prospective customers of his services," Danchev concludes.


Spotlight

Is it time to professionalize information security?
Posted on 23 May 2013. | The issue of whether or not information security professionals should be licensed to practice has already been the topic of many a passionate debate.

Review: Logging and Log Management
Posted on 22 May 2013. | Every security practitioner should be aware of the overwhelming advantages of logging and perusing logs for discovering system intrusions. But logging and log management comes with its own set of difficulties.

Experts highlight top data breach vulnerabilities
Posted on 22 May 2013. | Hidden vulnerabilities lie in everyday activities that can expose personal information and lead to data breach, including buying gas with a credit card or wearing a pacemaker.

A closer look at Mega cloud storage
Posted on 21 May 2013. | Once a novelty, nowadays many cloud storage services are fighting for their piece of the market in the virtual world. Mega offers 50GB of free space with great pricing on Pro accounts.

The CSO perspective on healthcare security and compliance
Posted on 20 May 2013. | Randall Gamby is the CSO of the Medicaid Information Service Center of New York. In this interview he discusses healthcare security and compliance challenges and offers a variety of tips.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.





