HomeSecurityHackers talk about how they bypass the 3D Secure protocol

Hackers talk about how they bypass the 3D Secure protocol

Cybercriminals are constantly discovering new ways to circumvent the 3D Secure (3DS) protocol used to authorize card transactions online.

Discussions in underground forums offer advice on how to bypass security protocol with a combination of social engineering and phishing attacks.

3D Secure

Hackers on multiple dark-web forums are sharing their knowledge about making fraudulent purchases at stores that implement the 3D Secure protocol to protect customer transactions.

3DS adds a layer of security to online purchases made with credit or debit cards. Immediate confirmation from the cardholder is required to authorize a payment.

The feature evolved from the first version where the bank asked the user for a code or static password to authorize the transaction. In the second version (3D Secure 2), designed for smartphones, users can confirm their purchase by authenticating in their banking app using their biometric data (fingerprint, facial recognition).

Despite the advanced security features provided by the 3DS 2, the first version is still widely used, giving cybercriminals the opportunity to use skills and trick users into giving up the code to authorize the transaction.

In a post today, analysts at Gemini Advisory share some of the methods cybercriminals are discussing on dark web forums to make fraudulent purchases at online stores that implement 3D Secure.

It all starts with the cardholder's full details, which include at least name, phone number, email, physical address, mother's maiden name, ID number, and driver's license number.

Cybercriminals use these details to pose as a bank employee calling the customer to verify their identity. By offering some personal information, they gain the victim's trust and ask for the code to complete the process.

The same tactic could work on later versions of the 3DS, allowing for real-time purchases. A hacker described this method in a post on an underground forum.

Using the cardholder's full details, a voice changer and a phone number spoofing app, the fraudster can initiate a purchase on a website and then call the victim to gather the necessary information.

Getting the 3DS code is also possible through other means, such as phishing. When the victim makes a purchase on the phishing website, the criminals forward all the details to the legitimate store to get the product.

According to Gemini Advisory's findings, some cybercriminals are also adding stolen credit card data to a PayPal and using it as a payment method.

Another method is classic and involves hacking a victim's phone with malware that can intercept the security code and transmit to the scammer.

Also, many stores don't ask for the 3DS code when transactions are below a certain threshold, allowing scammers to get away with making multiple smaller purchases.

Most of these techniques work with older versions of the 3DS. This doesn't seem to be the case with the 3DS 2. However, Gemini Advisory believes that cybercriminals will bypass the 3DS 2 protocol through social engineering.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS