The shift from payment cards with magnetic stripes to EMV chips was supposed to stomp out card cloning, except cybercriminals appear to have figured out a workaround.
With magnetic stripe cards, it was relatively easy for criminals to collect the information and copy onto a cloned card. In contrast, the EMV chip on the payment card encrypted the card number and personally identifiable information, making it harder to steal the data and create a cloned card. The EMV technology is also designed to generate a unique encryption key for each transaction where the card is present, so even if the criminal somehow had the card information, the encryption key to validate the transaction would be missing.
However, many companies still havent fully implemented EMV card readers, five years after the switch to EMV cards. That means card issuers have had to encode the card information on both the magnetic stripe and the EMV chip so that people can use the card both waysinserting the card in to the card reader or swiping the card. This is necessary for those situations when the user is in a country that doesnt have EMV terminals, or has to use an older point-of-sale terminal.
There is a subtle difference, though, because the magnetic stripe contains the card verification value (CVV), the three-digit code that is frequently printed on the back of the card, and the chip stores the a different code called the integrated circuit card verification value (iCVV).
Cybercriminals have been creating counterfeit cards by copying the EMV detailsincluding the iCVVonto the magnetic stripe. Since some banks dont verify that the magnetic stripe has the CVV and that the EMV chip has the iCVV, the criminals are able to use the magnetic stripe cards containing the EMV data, said cybersecurity company Gemini Advisory.
EMV technology may have changed the underground market for CP [card-present] records, but EMV-Bypass Cloning has opened the door for cybercriminals to sidestep the central security features of EMV chips and channel a new source of CP cards back into the underground CP market, Gemini Advisory said.
The fact that this was possible to do has been known since 2008,but the assumption was that banks would shift all their customers to using EMV cards and that magnetic stripe cards would disappear because everyone would have EMV point-of-sale terminals. The official switchover was back in 2015, and the idea was that banks would verify transactions carefully until a time when magnetic stripe cards would no longer be needed. The fact that some banks were not verifying CVV and iCVV correctly created this loophole.
It is looking very likely that this technique is already being used, Gemini Advisory said. Analysts looked at two recent incidents where criminals breached point-of-sale systems at supermarket chain Key Food Stores and liquor store Mega Package Store and captured EMV data for more than 720,000 payment cards. The magnetic stripe clones with the stolen data could be used in card-present transactions if the issuing bank doesnt properly verify the CVV.
While analysts have not found dark web chatter highlighting EMV-Bypass Cloning or malware capable of capturing such data from EMV-enabled POS devices, the Key Food Stores and Mega Package Store breaches came from two unrelated dark web sources, Gemini Advisory said. This indicates that the technique used to compromise this data is likely spreading across different criminal groups.
Gemini Advisorys findings comes shortly after researchers at Cyber R&D lab examined Visa and MasterCards issued by 11 banks in the United States, United Kingdom, and a few other countries in the European Union and found four cards were not properly verified. Researchers were able to make transactions using counterfeit magnetic stripe cards that were generated with data collected from EMV chip cards because those card issuers did not catch the fact that the cards were using iCVV instead of CVV.
In the past, cybercriminals typically did not target EMV data because there wasnt a clear way to monetize the information. The fact that the criminals are increasingly trying to steal EMV data suggests that is no longer the case. For example, Visa issued a warning recently that known point-of-sale malware families such as Alina, Dexter, and TinyLoader have been stealing payment card data from EMV chip-enabled point-of-sale terminals, according to Brian Krebs of KrebsonSecurity.com.
This problem can be solved. The banks need to verify which code is being used when approving payment transactions.
A higher verification standard involving data checks would raise the threshold of access and undercut fraudulent card use, Gemini Advisory concluded. EMV-Bypass Cloning is dangerously effective, but through policy review and higher verification standards, card providers and financial institutions can close the security gaps that this method exploits and restore the security integrity of EMV chips.
Read more:
Criminals Find a Way to Clone EMV Cards - Decipher
- What is Cloning? - Learn Genetics [Last Updated On: December 12th, 2016] [Originally Added On: December 12th, 2016]
- Pros and Cons of Cloning - Buzzle [Last Updated On: December 21st, 2016] [Originally Added On: December 21st, 2016]
- Cloning/Embryonic Stem Cells - National Human Genome Research ... [Last Updated On: December 22nd, 2016] [Originally Added On: December 22nd, 2016]
- Is human cloning wrong? | Debate.org [Last Updated On: December 25th, 2016] [Originally Added On: December 25th, 2016]
- Cloning - Science Daily [Last Updated On: December 29th, 2016] [Originally Added On: December 29th, 2016]
- Cloning - The New York Times [Last Updated On: January 4th, 2017] [Originally Added On: January 4th, 2017]
- Mammoth - Wikipedia [Last Updated On: January 24th, 2017] [Originally Added On: January 24th, 2017]
- Molecular Cloning: Basics and Applications | Protocol [Last Updated On: January 25th, 2017] [Originally Added On: January 25th, 2017]
- Beware Of 'Facebook Cloning' | 9news.com - 9NEWS.com [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Facebook scam lets hackers clone your account and STEAL money ... - Express.co.uk [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Beware of 'Facebook Cloning' | KGW.com - kgw.com [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Beware of Facebook 'cloning' scam - USA TODAY [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Facebook cloning debunked - The i newspaper online iNews - iNews [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Don't fall for this Facebook cloning scam | WFLA.com - WFLA [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- 20 years after Dolly the sheep, human cloning is no closer - Genetic Literacy Project [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Don't fall for this Facebook cloning scam | WDTN - WDTN [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- This Crab Clones Its Allies by Ripping Them in Half - The Atlantic [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Boffins create quantum cloning machine to intercept 'secure' messages - The INQUIRER [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Hair Cloning & Multiplication | Bernstein Medical [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Crustacean Cloning - ScienceBlog.com (blog) [Last Updated On: February 8th, 2017] [Originally Added On: February 8th, 2017]
- Watch out for this crazy Facebook cloning scam! - Komando [Last Updated On: February 8th, 2017] [Originally Added On: February 8th, 2017]
- Steve Bannon's Unproduced Movie About Cloning, Nazis, and Walt Disney Sounds Nuts - Gizmodo India [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Quantum Cloning Machine Reveals Clues That Could Protect Against Hacking - Photonics.com [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Steve Bannon wanted to make a movie about cloning, abortion, and Nazis with Mel Gibson - A.V. Club (blog) [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Police investigating recent reports of credit card cloning in Aiken ... - Aiken Standard [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Steve Bannon's Unproduced Movie About Cloning, Nazis, and Walt ... - Gizmodo [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Phone cloning - Wikipedia [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- Gang arrested for cloning debit cards, stealing money - The Hindu - The Hindu [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- Drive cloning in Windows 10 with free tools - Computerworld [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- Cloning - The Hastings Center [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- Scientists Are Close to Cloning a Woolly Mammoth - Popular Mechanics [Last Updated On: February 16th, 2017] [Originally Added On: February 16th, 2017]
- Antiquities Minister inaugurates first Pharaonic cloning center in Luxor - Egypt Independent [Last Updated On: February 18th, 2017] [Originally Added On: February 18th, 2017]
- 20 years after Dolly: Everything you always wanted to know about ... - Source [Last Updated On: February 18th, 2017] [Originally Added On: February 18th, 2017]
- 20 years after Dolly: Everything you always wanted to know about the cloned sheep and what came next - New Delhi Times [Last Updated On: February 20th, 2017] [Originally Added On: February 20th, 2017]
- 20 years after Dolly: Everything you always wanted to know about ... - The Conversation US [Last Updated On: February 20th, 2017] [Originally Added On: February 20th, 2017]
- Must reads: Populism, sexism, cloning, and rudeness - GlobalComment.com [Last Updated On: February 20th, 2017] [Originally Added On: February 20th, 2017]
- More lessons from Dolly the sheepis a clone really born at age ... - Phys.Org [Last Updated On: February 20th, 2017] [Originally Added On: February 20th, 2017]
- 15 Animals That Have Been Successfully Cloned by Scientists - Interesting Engineering [Last Updated On: February 21st, 2017] [Originally Added On: February 21st, 2017]
- Facebook does it again. WhatsApp launches revamped Status, cloning Snapchat - Catch News [Last Updated On: February 22nd, 2017] [Originally Added On: February 22nd, 2017]
- It's Been 20 Years Since We Cloned A Sheep. Why Haven't We Done The Same With Humans? - GOOD Magazine [Last Updated On: February 22nd, 2017] [Originally Added On: February 22nd, 2017]
- Reviving woolly mammoths will take more than two years - BBC News [Last Updated On: February 23rd, 2017] [Originally Added On: February 23rd, 2017]
- 20 years after Dolly the sheep's debut, Americans remain skeptical of cloning - Pew Research Center [Last Updated On: February 23rd, 2017] [Originally Added On: February 23rd, 2017]
- Another cloning success shows technology being used by everyday graziers - ABC Online [Last Updated On: February 24th, 2017] [Originally Added On: February 24th, 2017]
- 20 Years After Dolly, Where Are We With Cloning? - Inverse [Last Updated On: February 24th, 2017] [Originally Added On: February 24th, 2017]
- Pabrai And The Shameless Cloning Portfolio - Seeking Alpha [Last Updated On: February 24th, 2017] [Originally Added On: February 24th, 2017]
- As Clone Conspiracy Ends, the Fates of Two Major Spider-Man Villains Are Revealed - Gizmodo [Last Updated On: February 24th, 2017] [Originally Added On: February 24th, 2017]
- 20 years after Dolly the sheep, potential of cloning remains unclear - CNN [Last Updated On: February 24th, 2017] [Originally Added On: February 24th, 2017]
- More lessons from Dolly the sheep: Is a clone really born at age zero ... - Salon [Last Updated On: February 27th, 2017] [Originally Added On: February 27th, 2017]
- 20th Anniversary of Dolly the Cloned Sheep | Men's Health - Men's Health [Last Updated On: February 28th, 2017] [Originally Added On: February 28th, 2017]
- The Angels had two No. 97s on the basepaths, may be cloning their players - MLB.com [Last Updated On: March 1st, 2017] [Originally Added On: March 1st, 2017]
- 20 Years After Dolly: Cloning Past, Present and Future - KQED [Last Updated On: March 2nd, 2017] [Originally Added On: March 2nd, 2017]
- Facts About Cloning - Live Science [Last Updated On: March 2nd, 2017] [Originally Added On: March 2nd, 2017]
- Is Max cloning Tracey the barmaid to take over Walford in ... - Metro - Metro [Last Updated On: March 2nd, 2017] [Originally Added On: March 2nd, 2017]
- We know Dolly the sheep was cloned 20 years ago, but how old was she at birth? - Washington Post [Last Updated On: March 3rd, 2017] [Originally Added On: March 3rd, 2017]
- 'Miracle of nature' Scientists a step closer to HUMAN CLONING after creating mouse embryos - Express.co.uk [Last Updated On: March 3rd, 2017] [Originally Added On: March 3rd, 2017]
- Waxhaw police: Man charged with credit card cloning - WSOC Charlotte [Last Updated On: March 4th, 2017] [Originally Added On: March 4th, 2017]
- Facebook gives zero fucks about cloning Snapchat, adds geostickers in Instagram - TNW [Last Updated On: March 8th, 2017] [Originally Added On: March 8th, 2017]
- This man is cloning old-growth redwoods and planting them in safe places (video) - Treehugger [Last Updated On: March 9th, 2017] [Originally Added On: March 9th, 2017]
- Police warn of criminals cloning credit cards using stolen information - ABC Action News [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- Hard drive imaging vs. cloning: What's the difference? - Windows Central [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- Cloning Your VS 2017 Packages - Microsoft - Channel 9 (blog) [Last Updated On: April 8th, 2017] [Originally Added On: April 8th, 2017]
- Hair Cloning is Happening - NBC 5 Dallas-Fort Worth [Last Updated On: April 8th, 2017] [Originally Added On: April 8th, 2017]
- Woodbury Police Need Your Help In Credit Card Cloning Case - Patch - Patch.com [Last Updated On: April 8th, 2017] [Originally Added On: April 8th, 2017]
- Reasons Against Cloning - VIDEOS & ARTICLES [Last Updated On: April 8th, 2017] [Originally Added On: April 8th, 2017]
- B.o.B Talks Conspiracy Theories About 9/11, Snapchat, Cloning, Chemtrails, The Illuminati & More (VIDEO) - AllHipHop (blog) [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- International grifter gets 5 years in prison for Denver credit card cloning scam - The Denver Post [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- Send in the clones: Orphan Black, TV's smartest show, is back - The Guardian [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- Sorry, 'Jurassic Park' fans: Scientists say dinosaur cloning probably isn't going to happen - Travel+Leisure [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- Preparing winemakers for climate change through cloning - ABC Online [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- Skimming, cloning become popular in Tulsa - KRMG [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- Five Rules For Successful Marijuana Cloning [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- Cloning Grapes Will Save Australian Wine - National Geographic Australia [Last Updated On: June 8th, 2017] [Originally Added On: June 8th, 2017]
- Hackers caught cloning activist Twitter accounts to spread fake news - The Independent [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Cloning Yourself in Photos or Videos - Fstoppers [Last Updated On: June 11th, 2017] [Originally Added On: June 11th, 2017]
- Cloning to the rescue - New Scientist [Last Updated On: June 14th, 2017] [Originally Added On: June 14th, 2017]
- Cloning To Revive Abaco Wild Horses - Bahamas Tribune [Last Updated On: June 17th, 2017] [Originally Added On: June 17th, 2017]
- How Close Are We to Successfully Cloning the First Human? - Futurism [Last Updated On: June 22nd, 2017] [Originally Added On: June 22nd, 2017]
- Magnified: Cloning - The Hawk Eye (blog) [Last Updated On: June 24th, 2017] [Originally Added On: June 24th, 2017]
- Puppies cloned from ears arrive in Russia for genetic research ... - RT [Last Updated On: June 24th, 2017] [Originally Added On: June 24th, 2017]
- Three waiters arrested in Mumbai for fraud and cloning ATM cards ... - Hindustan Times [Last Updated On: June 26th, 2017] [Originally Added On: June 26th, 2017]