Citibank probes ATM withdrawals, cites potential U.S. retailer breaches'
It put a transaction block on some MasterCard debit and credit cards in Canada, Russia and the U.K.
Computerworld - Citibank has put a transaction block on an unspecified number of Citi-branded MasterCard debit and credit cards used in three countries because of fraudulent automated teller machine (ATM) cash-withdrawal activity, the company said in a statement yesterday.
The statement was issued after Boing Boing, a popular online blog site, carried a story detailing the problems a Citibank customer had while trying to access his account from Canadian ATM machines. The story suggested that the individual may have been the victim of ATM fraud involving Citibank cards in Canada, Russia and the U.K.
Apparently in response to widespread publicity about the blog posting, Citibank issued a brief statement confirming the ATM fraud without disclosing any details. Recently, we became aware of fraudulent ATM cash withdrawals on Citi-branded MasterCard credit and debit cards used in three countries on customer accounts that had been possibly compromised in previous retailer breaches in the U.S., the company said. To protect customer accounts that were affected, we placed a special transaction block in those three countries on PIN-based transactions.
The statement went on to add that Citibank is currently reissuing cards to affected customers. Protecting our customers accounts and personal information is one of our highest priorities, the statement said.
The fact that the fraud involves ATM cash withdrawals using personal identification numbers (PIN) suggests that it may be the result of massive "card-skimming" activity, said Avivah Litan, an analyst at Gartner Inc. in Stamford, Conn.
What seems to be happening at Citibank is that they are stopping ATM cash withdrawals, which means somebody got their PINs, Litan said. There are two general ways you can steal a PIN. One is through card skimming; the other is through phishing,
Given the apparent scope of the fraud, Litan pointed to card skimming as a likely cause.
Card skimming involves the use of illegal card-reading devices that intercept and record data stored on magnetic strips on credit and debit cards which are then later used to create counterfeit cards. Such devices, which have long been used to steal card information in places such as restaurants, have been proliferating widely and have made skimming one of the most prevalent forms of credit card fraud these days.
In fact, skimmers were believed to have been behind a massive credit card theft in December involving wholesaler Sams Club, a division of Wal-Mart Stores Inc.
In that incident, card skimmers were thought to have used skimming devices at Sams Club gas stations to steal debit card information from potentially thousands of consumers. At that time, Sams Club acknowledged that a breach had taken place, but did not disclose what exactly transpired saying only that electronic systems and databases used inside its stores were not involved.
Litan said it is likely that Citibanks current ATM fraud problems are related to the Sams Club breach.
Read more about Security in Computerworld's Security Topic Center.


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Driving Secure Enterprise File Sharing and Syncing in the Enterprise
- GroupLogic's new activEcho is the industry's only secure Enterprise File Sharing and Synching solution that balances the need for simplicity for the end...
- The Enterprise File Sharing Option
- Enterprises and IT departments need to address several critical security issues when considering file sharing and syncing products. Many of today's solutions do...
- Security Strategies to Virtualizing Internet-Facing Applications
- The IT organization at Intel has set a goal to transition their enterprise to a private cloud for their Office and Enterprise applications....
- Cloud Security Planning Guide
- Cloud security considerations span protecting hardware and platform technologies in the data center to enabling regulatory compliance and defending cloud access through different...
- Cloud Security Vendor Round Table
- This vendor round table guide will help you to evaluate different cloud technology vendors and service providers based on a series of questions... All Security White Papers
- Live Webcast
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute - Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT
In a recent study conducted by Ponemon Institute, fifty-five percent of respondents... - Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
- Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT
In a recent study conducted by Ponemon Institute, fifty-five percent of respondents... - Security Certifications 101 - BlackBerry and all those acronyms what do they mean and why they matter?
- FIPS, Common Criteria, CAPS, AISEP, NFC, NIST, Fraunhofer SIT, CESG, DSD - these are just some of the government and industry certifications which...
- BlackBerry PlayBook OS 2.0 Security Overview
- The presentation provides an overview of BlackBerry PlayBook OS 2.0 security capabilities and features, including: BlackBerry® Balance™ technology, BlackBerry® Bridge, data-at-rest protection, and...
- BlackBerry NFC Security Overview
- The presentation on NFC security will provide an overview of the security protections built into the BlackBerry platform to protect users, application developers...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts