December 6, 2016 By Douglas Bonderud 3 min read

Online orders are up. As noted by Business Insider, consumers spent $3.34 billion online this Black Friday, up 22 percent year over year and significantly exceeding predictions. Expect this trend to continue through the Christmas shopping season.

The rise of internet-based shopping offers a huge opportunity for cybercriminals, especially when it comes to credit cards. According to CIO, crooks are now crowdsourcing credential compromise through a “distributed guessing attack,” casting a wide net to zero in on key consumer details.

E-Commerce Evolution

Physical credit card fraud remains a problem for many companies. On average, 5.65 cents on every dollar is lost to credit card fraud, with almost half of it taking place in the U.S. Online shopping is the new sales juggernaut that issuers and retailers must effectively manage.

Consider the rise of mobile-based e-commerce. As noted by Beta News, 71 percent of consumers say they plan to make purchases using mobile this holiday season, while 43 percent will spend more than $250 via their mobile device. However, 64 percent of those surveyed said they have not installed a third-party mobile security application, yet 82 percent feel safe when shopping online.

In some cases, solid security hygiene can help prevent fraud. Consumers should only download reputable apps from authorized app stores, never click on malicious links and, according to the Iowa attorney general, opt for websites that contain the HTTPS designator in the URL. Unfortunately, though, best practices may no longer be enough.

20 Questions

How do popular retail sites limit credit card fraud? Most require multiple pieces of information to validate card use — typically card number, expiry date and card verification value (CVV) code — then limit users to a specific number of attempts to enter the correct information.

On a small scale, this works well enough. When fraudsters armed with credit card numbers, which are easily available in any Dark Web marketplace, fail to login multiple times, they are locked out of the accounts they are trying to break and cardholders are notified.

But a team of researchers at Newcastle University discovered that cybercriminals can get around this problem by leveraging stolen credit card numbers across multiple sites at once. Using its distributed guessing attack technique, the Newcastle team managed to crack card details in less than six seconds.

Distributed Guessing Attack

Empowering this effort are two key factors. First is the type of information required by the e-commerce site. Those asking for expiry data make it easy. Credit cards are typically valid for five years, giving a range of only sixty possible month/date combinations.

The second factor is the number of allowed guesses before getting locked out. For example, ferreting out the CVV is more difficult since it requires thousands of guesses. But even that remains a relatively easy endeavor, since there are at least that many shopping sites available online, many of which support 10 or 20 login attempts.

The researchers also discovered disparity between card issuers. MasterCard’s centralized payment network shut down multiple requests after less than 10 attempts regardless of website, while Visa’s distributed platform made it possible to pluck out the necessary details. And some sites that demanded address verification in addition to CVV and card number were vulnerable since some banks encoded branch details in credit cards, giving researchers a solid starting point to track down physical addresses.

Online shopping is on the rise, both through mobile and traditional desktop platforms. While users are becoming more savvy with their details, processors and e-commerce sites are inadvertently opening the door to increased online fraud. Where possible, don’t save credit data online and always follow up digital purchases with regular statement checks. Credit fraud can happen almost instantly if crooks decide to crowdsource.

More from

Cyberattack on American Water: A warning to critical infrastructure

3 min read - American Water, the largest publicly traded United States water and wastewater utility, recently experienced a cybersecurity incident that forced the company to disconnect key systems, including its customer billing platform. As the company’s investigation continues, there are growing concerns about the vulnerabilities that persist in the water sector, which has increasingly become a target for cyberattacks. The breach is a stark reminder of the critical infrastructure risks that have long plagued the industry. While the water utility has confirmed that…

What’s behind unchecked CVE proliferation, and what to do about it

4 min read - The volume of Common Vulnerabilities and Exposures (CVEs) has reached staggering levels, placing immense pressure on organizations' cyber defenses. According to SecurityScorecard, there were 29,000 vulnerabilities recorded in 2023, and by mid-2024, nearly 27,500 had already been identified.Meanwhile, Coalition's 2024 Cyber Threat Index forecasts that the total number of CVEs for 2024 will hit 34,888—a 25% increase compared to the previous year. This upward trend presents a significant challenge for organizations trying to manage vulnerabilities and mitigate potential exploits.What’s behind…

Quishing: A growing threat hiding in plain sight

4 min read - Our mobile devices go everywhere we go, and we can use them for almost anything. For businesses, the accessibility of mobile devices has also made it easier to create more interactive ways to introduce new products and services while improving user experiences across different industries. Quick-response (QR) codes are a good example of this in action and help mobile devices quickly navigate to web pages or install new software by simply scanning an image.However, legitimate organizations aren’t the only ones…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today