Cybersecurity (opens in new tab) researchers have revealed hackers have discovered a way to find card numbers without breaking into a database, and there’s also a booming underground black market for them.
Researchers at popular VPN (opens in new tab) service provider, NordVPN analyzed statistical data that was collated by independent researchers from dark web markets and learnt that most of the card numbers sold on the dark web are brute forced.
The attackers are able to pull this off because the digits on most cards follow a fixed pattern, and can be deduced. For instance, the first couple of digits indicate the financial service provider, while the sixteenth is a checksum, and so on. Furthermore, the CVV is made up of three digits, which also helps with the guesswork.
We're looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and we'd hugely appreciate if you'd share your experiences with us.
>> Click here to start the survey in a new window (opens in new tab) <<
“Clever hackers can significantly cut down how many numbers they need to guess and check to find your payment card number. In fact, researchers at Newcastle University estimate that an attack like this could take as few as six seconds,” note (opens in new tab) the researchers, adding that an average hacked card’s data costs less than $10.
Crunching the available data, NordVPN says that of the 4,481,379 stolen cards, the maximum (1,561,739) belonged to US citizens. By comparison, only 134,607 cards for sale on the dark web belonged to UK residents.
Also, the researchers discovered that debit cards were more common than credit cards (opens in new tab), which is particularly worrisome since NordVPN says that debit cards don’t have the same level of protections as credit cards. Furthermore, Visa (opens in new tab) cards were the most common, followed by Mastercard (opens in new tab), and American Express (opens in new tab).
“There is little that users can do to protect themselves from this threat short of abstaining from card use entirely,” note the researchers, suggesting that users should keep an eye out for suspicious entries in their statements.
Shield yourself online with these best identity theft protection services (opens in new tab)