Target hackers have more data to sell as demand wanes
Those who stole the data appear to be keeping a low profile on underground forums
IDG News Service - What's the downside to successfully stealing 40 million credit card numbers from Target? Trying to sell the data.
There's a thriving economy among cybercriminals, some of whom specialize in stealing credit card numbers to others who figure out a way to profit. But it's also constrained by supply and demand.
Too many card numbers on the market inevitably drives the price of a set of details down. Card information, referred to in underground forums as "dumps," are often priced according to how recently the details were stolen, its likely spending limit and whether the hackers have captured a PIN for the card.
Prices can range from a few dollars up to $100. Cybercriminals often advertise the kind of data they've captured from the card's magnetic stripe, which has three so-called "tracks," each containing data.
"Track 1" data contains a card number, the victim's name and the card's expiration data, and Track 2 data contains the card number and expiration data. The third track is rarely used.
"You can imagine that having a lot of stolen credit cards will not net the hackers, say $35 per card for all 40 million," said Alex Holden, who runs a cybercrime consultancy, Hold Security. "Even if the hackers are willing to sell cards for $1 a card, no one will buy the stolen goods in these amounts."
Target said attackers likely intercepted 40 million debit and credit card numbers between Nov. 27 to Dec. 15, 2013, one of the busiest shopping periods in the U.S. Target CEO Gregg Steinhafel said in an interview with CNBC on Sunday that malware was discovered on point-of-sale terminals.
How those terminals were infected is still a mystery. Computer security experts are keeping a close eye on underground forums where the data is traded, looking for clues as to who may be responsible.
So far, they haven't seen much.
"We have seen some comments by other hackers that would suggest that there was no sound exist strategy by the thieves," Holden said. "Right now, they are maybe laying low knowing that everyone is looking for them."
Send news tips and comments to firstname.lastname@example.org. Follow me on Twitter: @jeremy_kirk
- 15 Non-Certified IT Skills Growing in Demand
- How 19 Tech Titans Target Healthcare
- Twitter Suffering From Growing Pains (and Facebook Comparisons)
- Agile Comes to Data Integration
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
- Who's Spying on You? You're aware of the threats of malware to your business but what about the ever-changing ground rules? Cybercriminals today are launching attacks against...
- Pay-as-you-Grow Data Protection: IBM Tivoli's Full-featured Data Protection Suite for Small to Medium Businesses IBM Tivoli Storage Manager Suite for Unified Recovery gives small and medium businesses the opportunity to start out with only the individual solutions...
- Streamline Data Protection with IBM Tivoli Storage Manager Operations Center IBM Tivoli Storage Manager (TSM) has been an industry-standard data protection solution for two decades. But, where most competitors focus exclusively on Backup...
- Simplify and Consolidate Data Protection for Better Business Results Learn about IBM® Tivoli® Storage Manager Operations Center, which provides advanced visualization, built-in analytics and integrated workflow automation features that leapfrog traditional backup...
- Meg Whitman presents Unlocking IT with Big Data During this Web Event you will hear Meg Whitman, President and CEO, HP discuss HAVEn - the #1 Big Data platform, as well...
- The New Way to Work Knowledge Vault This Knowledge Vault focuses on how, in today's increasingly virtual world, it's more important than ever to engage deeply with employees, suppliers, partners,... All Cybercrime and Hacking White Papers | Webcasts