December 6, 2016 By Douglas Bonderud 3 min read

Online orders are up. As noted by Business Insider, consumers spent $3.34 billion online this Black Friday, up 22 percent year over year and significantly exceeding predictions. Expect this trend to continue through the Christmas shopping season.

The rise of internet-based shopping offers a huge opportunity for cybercriminals, especially when it comes to credit cards. According to CIO, crooks are now crowdsourcing credential compromise through a “distributed guessing attack,” casting a wide net to zero in on key consumer details.

E-Commerce Evolution

Physical credit card fraud remains a problem for many companies. On average, 5.65 cents on every dollar is lost to credit card fraud, with almost half of it taking place in the U.S. Online shopping is the new sales juggernaut that issuers and retailers must effectively manage.

Consider the rise of mobile-based e-commerce. As noted by Beta News, 71 percent of consumers say they plan to make purchases using mobile this holiday season, while 43 percent will spend more than $250 via their mobile device. However, 64 percent of those surveyed said they have not installed a third-party mobile security application, yet 82 percent feel safe when shopping online.

In some cases, solid security hygiene can help prevent fraud. Consumers should only download reputable apps from authorized app stores, never click on malicious links and, according to the Iowa attorney general, opt for websites that contain the HTTPS designator in the URL. Unfortunately, though, best practices may no longer be enough.

20 Questions

How do popular retail sites limit credit card fraud? Most require multiple pieces of information to validate card use — typically card number, expiry date and card verification value (CVV) code — then limit users to a specific number of attempts to enter the correct information.

On a small scale, this works well enough. When fraudsters armed with credit card numbers, which are easily available in any Dark Web marketplace, fail to login multiple times, they are locked out of the accounts they are trying to break and cardholders are notified.

But a team of researchers at Newcastle University discovered that cybercriminals can get around this problem by leveraging stolen credit card numbers across multiple sites at once. Using its distributed guessing attack technique, the Newcastle team managed to crack card details in less than six seconds.

Distributed Guessing Attack

Empowering this effort are two key factors. First is the type of information required by the e-commerce site. Those asking for expiry data make it easy. Credit cards are typically valid for five years, giving a range of only sixty possible month/date combinations.

The second factor is the number of allowed guesses before getting locked out. For example, ferreting out the CVV is more difficult since it requires thousands of guesses. But even that remains a relatively easy endeavor, since there are at least that many shopping sites available online, many of which support 10 or 20 login attempts.

The researchers also discovered disparity between card issuers. MasterCard’s centralized payment network shut down multiple requests after less than 10 attempts regardless of website, while Visa’s distributed platform made it possible to pluck out the necessary details. And some sites that demanded address verification in addition to CVV and card number were vulnerable since some banks encoded branch details in credit cards, giving researchers a solid starting point to track down physical addresses.

Online shopping is on the rise, both through mobile and traditional desktop platforms. While users are becoming more savvy with their details, processors and e-commerce sites are inadvertently opening the door to increased online fraud. Where possible, don’t save credit data online and always follow up digital purchases with regular statement checks. Credit fraud can happen almost instantly if crooks decide to crowdsource.

More from

AI cybersecurity solutions detect ransomware in under 60 seconds

2 min read - Worried about ransomware? If so, it’s not surprising. According to the World Economic Forum, for large cyber losses (€1 million+), the number of cases in which data is exfiltrated is increasing, doubling from 40% in 2019 to almost 80% in 2022. And more recent activity is tracking even higher.Meanwhile, other dangers are appearing on the horizon. For example, the 2024 IBM X-Force Threat Intelligence Index states that threat group investment is increasingly focused on generative AI attack tools.Criminals have been…

The major hardware flaw in Apple M-series chips

3 min read - The “need for speed” is having a negative impact on many Mac users right now. The Apple M-series chips, which are designed to deliver more consistent and faster performance than the Intel processors used in the past, have a vulnerability that can expose cryptographic keys, leading an attacker to reveal encrypted data. This critical security flaw, known as GoFetch, exploits a vulnerability found in the M-chips data memory-dependent prefetcher (DMP). DMP’s benefits and vulnerabilities DMP predicts memory addresses that the…

NIST’s role in the global tech race against AI

4 min read - Last year, the United States Secretary of Commerce announced that the National Institute of Standards and Technology (NIST) has been put in charge of launching a new public working group on artificial intelligence (AI) that will build on the success of the NIST AI Risk Management Framework to address this rapidly advancing technology.However, recent budget cuts at NIST, along with a lack of strategy implementation, have called into question the agency’s ability to lead this critical effort. Ultimately, the success…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today