The unstoppable Credit Card blackmarket(stopthehacker.com) |
The unstoppable Credit Card blackmarket(stopthehacker.com) |
Well, luckily I was poor and 16 when they bounced and locked my card up right away(never buying from that tshirt store again).
Years down the line though, I still can find my name, old cc, and address on these lists. They're all over IRC...
On the topic of scamming, most of them use a reputation based system (ie. traderx has 60 successful transactions, while traderb has -3 successful transactions; who would you go with?)
You can also hire moderators to check out some things, iirc. Such as, placing a $0.03 charge through a merchant and verifying or checking the accounts.
I did a pretty large study of this back in 2003 or so, but really lost interest once I pissed off the wrong people and they got personal.
I'll never forget it, he not only told me my mother's name, but also read off her social security number and told me it was 'disgusting pig' she was on welfare. (born with CP)
That shock (the shock of involvement of family) led me to ditching all my research and moving on to writing papers on Cisco routers.
That was back in 2001, finding identities and ssn's wasn't quite so easy; especially for an invalid mother who had never ventured near a keyboard. On reflection, I suppose it wasn't too hard even then to obtain info if you had money, but still creepy to have some international guy threaten your life/your mother's life for gathering info.
This actually happened again recently, but the shock wasn't quite there. This time, my girlfriend was attacked by an angry blackhat SEO because I was treading on his niche territory. Its not too hard to tie adwords campaigns > domains > domain whois > real name > facebook/social networking > family and get info on them these days. This guy contacted me first too, but moved on to harassing my girlfriend. Domain parking, go go. Its not worth the $15 a month to get harassed. I'm pretty sure he got my adsense account banned (suspicious clicks) + had something going on to click my ads automatically and waste my money (I had a 15% CTR at one point). Also my wordpress had someone logged into my admin at one point, but I've basically turned my linode into knox since then.
She didn't quite seem to understand why I was in a panic over the situation...
It's against Western Union's interest to extensively document everyone and every dollar that passes through their systems. I'm sure they comply with the legal requirements placed on them, but I doubt they go WAY beyond that, for doing so would not be in their best business interests
Is it:
-- Incompetence? Leadership, technical, other? -- Low visibility to law enforcement? (In which case, why?) -- Priorities? Well-placed? Misplaced? -- Strategic? For ethical purposes?
The problem needs fixing, but it seems important understanding why we're at this point today when enforcement seems to obvious and simple. There's more than enough enforcement power available, at least in the U.S., to deal with the brazen criminals and make it much harder for them. Are those honeypots?
Is there some non-obvious reason that it's in the interest of the CC companies to let this go? Is there a lot of low-level fraud that customers never notice, and just keep making those monthly minimum payments?
So, >CC Thief gets whatever he bought at an empty house >CC holder gets stuck in an infinite customer service loop >CC company avoids charges >Seller gets fined
It would actually be interesting to see how "legitimate" CC sellers try to distinguish themselves from the fakes. They mention in the article that some of them are using images to identify themselves, effectively creating CC hacker brands.
Edit: ambiate makes a good point about reputation systems on the forums they use. Seems practical and discourages username swapping.
You'd think if the harvester has the ability to harvest, he'd be able to work out a better way of monetizing credit cards than selling them at $2 a pop.
Or, maybe I just misunderstand how the people who buy the lists monetize the credit card info.