Bank of the West is warning that customers' debit card numbers and PINs have been stolen by skimmers installed in many of the bank's ATMs. The financial institution, which operates more than 600 branches in the United States, first detected a wave of suspicious withdrawal attempts late last year, specifically in November. It immediately began working with law enforcement to conduct an investigation .

The audit of the entire Bank of the West ATM network was completed on April 18, 2022, and showed that someone had installed skimmers in many ATMs .
See also: Android malware Revive masquerades as Spanish bank's 2FA app
“ The skimming device installed in ATMs interfered with the normal debit card transaction and allowed the theft of card , the PIN number associated with your card, and possibly your name and address your number ,” the bank explains in its notice
“This stolen information may have been used to create fake debit cards and attempt to withdraw cash.“.
Bank of the West claims it immediately stopped the fraudulent use details and actively monitored all accounts found to have been compromised.
See also: USA, Brazil: Removal of 272 sites that allowed illegal music downloads
Customers whose credit cards have been compromised will receive a new debit card and PIN, while the previous ones have been blocked by the bank. In addition, the bank said it will offer a free one-year subscription to Identity Guard® Total, a service that takes care of identity monitoring and protection. Aura Identity Guard Total provides essential credit data, while also monitoring the Dark Web and notifying if social security numbers, credit cards and bank account numbers are on unsafe online sites.

Skimmers at ATMs
Typically, fraudsters choose to steal debit and credit card details by hacking online stores. Fraudsters secretly execute JavaScript code on the checkout pages of e-commerce sites , collecting the details entered at the checkout stage. However, in these cases, attackers cannot make direct withdrawals at ATMs, as they do not have the card’s magnetic stripe or PIN data. Thus, fraudsters mainly exploit the stolen cards by making online purchases. Because the victim can become aware of the breach and report it, some of the fraudulent transactions may be reversed and the damage can be limited.
See also: Vice Society: Ransomware attack on University of Innsbruck
In the case of Bank of the West and ATM skimmers, stolen information is used to create cloned cards that function like real ones, so attackers can empty accounts victims'
At this time, Bank of the West has not officially reported the number of compromised debit cards.
Source: www.bleepingcomputer.com
