Fraudsters Circumvent 3D Secure with Social Engineering

Fraudsters Circumvent 3D Secure with Social Engineering

Cyber-criminals are actively sharing tips and advice on how to bypass the 3D Secure (3DS) protocol to commit payment fraud, according to researchers.

A team at threat intelligence firm Gemini Advisory found the discussions on multiple dark web forums, claiming that phishing and social engineering tactics stood a good chance of success in certain situations.

Although version two of the protocol, designed for smartphone users, allows individuals to authenticate payments with hard-to-spoof or steal biometric information, earlier, less secure versions are still widely used, the firm claimed.

Use of a static password to authenticate exposes shoppers to such scams. Fraudsters could buy personal information on a user, call them up impersonating their bank and then provide some of this info to ‘prove’ their legitimacy, before asking for the password, Gemini Advisory said.

The firm’s analysts have also eavesdropped on reputable hackers offering advice on how to make purchases in real-time, bypassing two-factor authentication (2FA) codes. They enter stolen payment card details into an e-commerce site, then call the cardholder spoofing their number to appear as if they’re calling from the bank. When the 2FA code comes through, they request it from the victim.

Mobile malware could also be used to intercept 2FA numbers sent by SD3 v 1 to shoppers, the report noted.

Other scams designed to circumvent 3DS include phishing pages, which can be used to harvest static passwords, and use of PayPal. The latter would first require the purchase of credit card details plus bank account logins, then a fraudster could add the card to the relevant PayPal account, Gemini Advisory said.

Another scam discussed on dark web sites involves smaller purchases.

“In order to simplify the purchase process, some online shops disable the 3DS feature for smaller purchases, which, depending on the shop, can be in the hundreds of dollars. For example, transactions less than $30 are exempted, but not if the card is used five times or if the total charges exceed $100,” Gemini said.

“Other sites have their own requirements, sometimes as high as $400. Cyber-criminals can test these sites to determine which purchase amount triggers the 3DS, and then keep the purchases under those amounts.”

Although SD3 v2 is more secure, it is not impervious to “well-honed social engineering skills,” the report concluded.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

SITA Supply Chain Breach Hits Multiple Airlines

SITA Supply Chain Breach Hits Multiple Airlines

A major aviation IT company has been breached in what appears to be a coordinated supply chain attack affecting multiple airlines and hundreds of thousands of passengers.

SITA provides IT and telecoms services to around 400 members in the industry, claiming to serve around 90% of the global airline business.

It revealed yesterday that attackers had compromised passenger data stored on its SITA Passenger Service System servers in the US. It said these servers operate passenger processing systems for airline clients.

“After confirmation of the seriousness of the data security incident on February 24 2021, SITA took immediate action to contact affected SITA PSS customers and all related organizations,” it continued.

“We recognize that the COVID-19 pandemic has raised concerns about security threats, and, at the same time, cyber-criminals have become more sophisticated and active. This was a highly sophisticated attack.”

The company had little else to disclose at this stage except that it acted swiftly to try and contain the threat and that incident responders and third-party experts are continuing to monitor the situation.

It’s believed that the attack was responsible for the Malaysia Airlines breach which compromised its Enrich frequent flyer data between 2010 and 2019.

Singapore Airlines also released a statement this week to the same effect. Although the airline said it is not a customer of SITA, the attackers managed to compromise its KrisFlyer and PPS members’ data via a fellow Star Alliance member.

“Around 580,000 KrisFlyer and PPS members have been affected by the breach of the SITA PSS servers,” it noted in a statement.

“The information involved is limited to the membership number and tier status and, in some cases, membership name, as this is the full extent of the frequent flyer data that Singapore Airlines shares with other Star Alliance member airlines for this data transfer.”

Other airlines affected by the SITA breach included Finnair, which said 200,000 frequent flyers were impacted.

Ran Nahmias, co-founder of Cyberpion, argued the attacks highlight the risks involved in modern IT supply chains.

“When you consider the need to monitor the potential risks across a vast ecosystem that includes vector-associated DNS management, cloud providers, web properties, encryption, certificates and mobile infrastructures, the modern IT organization is not prepared to monitor, let alone manage, that risk,” he said.

“This is an environment where hackers and malicious actors thrive. When there is a lack of clearly defined oversight and management processes, hackers are able to operate freely and inflict significantly more damage.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

No, RSA Is Not Broken

I have been seeing this paper by cryptographer Peter Schnorr making the rounds: “Fast Factoring Integers by SVP Algorithms.” It describes a new factoring method, and its abstract ends with the provocative sentence: “This destroys the RSA cryptosystem.”

It does not. At best, it’s an improvement in factoring — and I’m not sure it’s even that. The paper is a preprint: it hasn’t been peer reviewed. Be careful taking its claims at face value.

Some discussion here.

I’ll append more analysis links to this post when I find them.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk