HomeSecurityBiometric skimmers are here: the upcoming threats to ATMs

Biometric skimmers are here: the upcoming threats to ATMs

Kaspersky Lab experts have investigated how cybercriminals can exploit new ATM authentication technologies being developed by banks. While many financial institutions view biometric-based solutions as the most promising additions to existing authentication methods, or even an option to replace them, cybercriminals see the use of biometrics as a new opportunity to steal sensitive information.

ATMs have been the target of fraudsters for years, hunting for credit card data. It all started with primitive “skimmers” – homemade devices placed in an ATM that could steal information from the card’s magnetic stripe, as well as the corresponding PIN code, using a fake ATM keypad or webcam.

ATM

Over time, the design of these devices has improved to make them less visible. With the introduction of “chip-and-pin” technology on payment cards, which made their “cloning” very difficult but not impossible, the devices have evolved from “skimmers” to “shimmers”: largely the same, but with the ability to collect information from the card’s microchip, providing sufficient information to carry out a cyber attack. The banking sector is responding with new identification solutions, some of which are based on biometrics.

According to Kaspersky Lab's research into the "underground" digital crime, there are already at least a dozen vendors providing skimmers that have the ability to steal victims' fingerprints, as well as at least three vendors already developing devices that could illegally obtain data from palm or iris recognition systems.

The first “wave” of biometric skimmers was studied during “tests” in September 2015. The data collected by Kaspersky Lab researchers reveals that during the initial tests, the developers discovered several bugs. However, the main problem was the use of GSM data to transfer biometric data – it was too slow to transfer the large amount of data being collected. As a result, new versions of the skimmers will use other, faster technologies to transfer data.

There are also indications of ongoing discussions among underground communities about developing mobile applications that rely on placing masks over the human face. With such an application, attackers could take a person's photo posted on social media and use it to fool facial recognition systems.

“The problem with using biometrics is that, unlike passwords or PINs that can be easily changed in the event of a breach, it is impossible to change your fingerprints or iris image. So, even if your data is compromised once, it will not be safe to use this authentication method again. For this reason, it is extremely important to keep your data safe and transmit it in a secure manner. Biometric data is also recorded in modern passports – called e-passports – in visas, etc. So, if an attacker steals an e-passport, they not only have the document, but also the person’s biometric data. In essence, their very identity has been stolen!” said Olga Kochetova, security expert at Kaspersky Lab.

The use of tools capable of compromising biometric data is not the only potential digital threat facing ATMs, according to Kaspersky Lab researchers. Hackers will continue to conduct malware-based attacks, blackbox attacks, and network attacks to exploit data that can later be used to steal money from banks and their customers.

For the full report on upcoming digital threats to automated teller machines (ATMs) and the measures that can protect banks from these threats, you can visit the dedicated website Securelist.com.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS