
The U.S. Department of Justice said it has arrested 18 international cybercriminals who committed various financial frauds and stole tens of millions of dollars from financial institutions and individuals using the Skimming method. The hackers aimed to remove money from ATMs and launder proceeds from illegal activities, while also stealing more than $20 million in 17 different countries.
According to Geoffrey S. Berman, a New York attorney, the hackers were charged with committing a variety of crimes, including bank fraud, device fraud and identity theft. The 18 defendants imported skimming devices from various countries and placed them in ATMs to capture debit card information and identification numbers when victims used the ATMs. The stolen information was then used to fraudulently withdraw cash from the victims’ bank accounts.
“The Skimming operation illegally obtained information from accounts by using advanced technological devices to covertly record debit card numbers and personal identification numbers at automated teller machines and then manufacture counterfeit and deceptive debit cards. The Skimming operation then used these cards to fraudulently withdraw cash from the victims’ bank accounts,” the Department of Justice said in its report.
“If found guilty, each defendant will be charged with committing access fraud, which carries a maximum sentence of 7.5 years in prison, conspiracy to commit systemic and bank fraud, which carries a maximum sentence of 30 years in prison, and identity theft, which carries a mandatory sentence of two years in prison, in addition to any other sentence imposed,” the report added.
Recently, security experts discovered a malware designed to exploit Indian bank ATMs to steal sensitive customer information. The malware, called ATMDtrack, allows attackers to read and store customer card data when inserted into infected ATMs.
According to Konstantin Zykov, a researcher at Kaspersky Labs, the attacker who created ATMDtrack has been identified as a member of the Lazarus Group, which is controlled by North Korea's intelligence agency. The infamous Lazarus Group is the main suspect in a series of cyberattacks, including the 2014 Sony Pictures Entertainment hack and the 2017 WannaCry ransomware attack
