Debit Card Fraud

2»

Comments

  • RG2015
    RG2015 Posts: 6,043 Forumite
    Ninth Anniversary 1,000 Posts Name Dropper Photogenic
    eskbanker said:
    They are not randomly guessed. They are compromised at some point where the card has been used.
    OP clarified that:
    RG2015 said:
    the debit card has never been used and never even been out of a drawer in my house.
    My understanding is that numbers are (sometimes) effectively guessed randomly by brute force number-generating attacks....
    Yes but can you match a brute forced 16 digit number that matches a brute forced expiry date?

    It would appear so.
  • RG2015
    RG2015 Posts: 6,043 Forumite
    Ninth Anniversary 1,000 Posts Name Dropper Photogenic
    k_man said:
    Similar discussion here:

    https://forums.moneysavingexpert.com/discussion/comment/79633980/#Comment_79633980

    While the details may have been compromised elsewhere, the use of Amazon, a retailer that doesn't require CVV, and a card that has never been used online or in person, suggests otherwise.

    ETA: so more likely a number generator was used, against a week retailer system to brute force the expiry.

    @RG2015, which bank was this with?
    My instance was TSB, as was one of the banks in the linked thread, albeit that may just be coincidence.
    It was the Royal Bank of Scotland.

    I absolutely agree that it suggests otherwise and that is the problem. 

    As Sherlock Holmes says, all the remains is the improbable, however unlikely.

    Brute forced 16 digit number and expiry date which is all Amazon require. 
  • RG2015
    RG2015 Posts: 6,043 Forumite
    Ninth Anniversary 1,000 Posts Name Dropper Photogenic
    k_man said:
    Forgot to add, in my instance, card had never been used, including on Amazon. The purchase was on someone else's Amazon account.

    I found it on the bank account, as @RG2015 did.
    Good point.

    It clearly is not on my Amazon account so it must be someone else's account.

    However it is screwing with my brain so much I have just checked my Amazon account. And guess what?

    There's nothing there!   :)
  • eskbanker
    eskbanker Posts: 36,928 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    RG2015 said:
    eskbanker said:
    They are not randomly guessed. They are compromised at some point where the card has been used.
    OP clarified that:
    RG2015 said:
    the debit card has never been used and never even been out of a drawer in my house.
    My understanding is that numbers are (sometimes) effectively guessed randomly by brute force number-generating attacks....
    Yes but can you match a brute forced 16 digit number that matches a brute forced expiry date?

    It would appear so.
    Yes - for any given 16 digit generated card number, there will only be something like 36 to 60 possibilities for current expiry date, so that's not much of a multiplying factor if you're already working with 10^16 options.
  • Eco_Miser
    Eco_Miser Posts: 4,820 Forumite
    Part of the Furniture 1,000 Posts Photogenic Name Dropper
    eskbanker said:
    RG2015 said:
    eskbanker said:
    They are not randomly guessed. They are compromised at some point where the card has been used.
    OP clarified that:
    RG2015 said:
    the debit card has never been used and never even been out of a drawer in my house.
    My understanding is that numbers are (sometimes) effectively guessed randomly by brute force number-generating attacks....
    Yes but can you match a brute forced 16 digit number that matches a brute forced expiry date?

    It would appear so.
    Yes - for any given 16 digit generated card number, there will only be something like 36 to 60 possibilities for current expiry date, so that's not much of a multiplying factor if you're already working with 10^16 options.
    Not that you're really working with 10^16 options. The first four (or more) digits indicate Visa/Mastercard etc and the bank, the last is a check digit. I'm sure anyone with an interest (legitimate or otherwise) in the construction of 16 digit card numbers can find the relevant IDs and algorithms easily enough.

    Eco Miser
    Saving money for well over half a century
  • eskbanker
    eskbanker Posts: 36,928 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    Eco_Miser said:
    eskbanker said:
    RG2015 said:
    eskbanker said:
    They are not randomly guessed. They are compromised at some point where the card has been used.
    OP clarified that:
    RG2015 said:
    the debit card has never been used and never even been out of a drawer in my house.
    My understanding is that numbers are (sometimes) effectively guessed randomly by brute force number-generating attacks....
    Yes but can you match a brute forced 16 digit number that matches a brute forced expiry date?

    It would appear so.
    Yes - for any given 16 digit generated card number, there will only be something like 36 to 60 possibilities for current expiry date, so that's not much of a multiplying factor if you're already working with 10^16 options.
    Not that you're really working with 10^16 options. The first four (or more) digits indicate Visa/Mastercard etc and the bank, the last is a check digit. I'm sure anyone with an interest (legitimate or otherwise) in the construction of 16 digit card numbers can find the relevant IDs and algorithms easily enough.
    While it's true that the first six (BIN) digits do indeed denote the actual product ranges (which are published), they do still exist, but yes, if you're looking to generate card numbers specifically within a given BIN then you've reduced the number of options down to 10^9 (allowing for check digit).  However, my point was that if you're already having to generate valid numbers from quadrillions, trillions or even billions of options, a further multiplier of 36-60 is unlikely to be a significant deterrent....
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 350.3K Banking & Borrowing
  • 252.9K Reduce Debt & Boost Income
  • 453.2K Spending & Discounts
  • 243.3K Work, Benefits & Business
  • 597.8K Mortgages, Homes & Bills
  • 176.6K Life & Family
  • 256.4K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.