United States District Court Judge John Gleeson, who is presiding over In re Payment Card Interchange Fee and Merchant Discount Antitrust Litigation, has ruled that this website and others like it posted certain information regarding the settlement of that case that was misleading. Additional information as to class members' rights and options under the settlement is available at www.paymentcardsettlement.com.
Sign In

The Association for Convenience & Fuel Retailing

Skip Navigation LinksNACS Online / Magazine / Past Issues / 2010 / March 2010 / Day at the Breach: Not Just Cards, Keyboards Too

Day at the Breach: Not Just Cards, Keyboards Too

Day at the Breach: Not Just Cards, Keyboards Too
A Qualified Security Assessor at the PCATS annual conference in New Orleans this January mentioned to attendees that cyber-thieves are targeting automated clearing house (ACH) transactions to drain checking accounts.

Thieves inject "key loggers" into PCs, usually through email or unsecure Web site vectors, that constantly sift through entered and transmitted data on the unsuspecting user’s PC. Of particular value to these thieves: access credentials and routing and transfer information for a business or consumer checking account. Exploiting a security flaw in the ACH system â€" whereby the transactions are not verified (e.g., by PIN) and are not cleared in real time â€" thieves clean out accounts before anyone notices the cash is gone.

Recently, according to this QSA, one small jewelry merchant was cleaned out of $1 million in less than 36 hours this way. The thieves obtained all the credential and account information to access the main account, but how they transferred the money is ingenious. They took out an employment ad for a fictitious business and "hired" about 100 applicants; requesting their bank account details "in order to set up direct payroll deposit."

The thieves then transferred $9,999 into each "employee account" (under the IRS red flag amount) by accessing the chain’s disbursement account with the stolen credentials.

The next day, the thieves wrote ACH transfers on the "employee" accounts to deposit in a central European bank â€" and the money was promptly withdrawn as cash.

Think your online banking system is safe? So did this chain. Install anti-malware and anti-virus software, and keep them up to date. Also consider using a dedicated, secure PC for all online bank transactions â€" you never know who’s watching your keyboard.

PCI Compliance
Just starting out with PCI compliance? NACS can help guide you through the process. Learn more.

NACS EZ PCI
Need help with PCI compliance? NACS EZ PCI simplifies the compliance process so you can complete your self-assessment questionnaire (SAQ) with speed, ease and confidence. Choose the product that best fits your needs at nacsonline.com/ezpci