Usually, the cloning of a card requires the plastic to be scanned by a reader prepared to duplicate its information, but times have changed, as have extraction methods. A group of researchers at the University of Newcastle demonstrated the effectiveness of distributed attacks in “guessing” unknown parameters about a credit or debit card, including the expiration date and its CVV. How much time is needed? Between four and six seconds.

You Can “Clone” a Credit Card in 6 Seconds
Cards

One of the stupidest actions (I apologize for the expression) a person can do on social media is photographing and sharing their credit and/or debit cards. Unfortunately, those users have no idea about the risks of publishing data like the sixteen main digits and the expiration date. In fact, there are e-commerce portals on the Web that barely request those two fields to start a transaction. Most sites ask the user for a third value, the card's security code (CVV), which serves as a containment barrier against possible theft of the previous fields. The problem... is that the CVV can be calculated by brute force.

You Can “Clone” a Credit Card in 6 Seconds
With the full number and expiration date, calculating the card's CVV with a distributed attack is a matter of seconds.

This is what a team of researchers at the University of Newcastle has demonstrated. First of all, it is necessary to note that this technique is effective due to the lack of a general standard among e-commerce sites to protect their transactions. The researchers used Alexa's “Top 400” online sales list (389 was the final number), and from there established the robustness of each one. 291 sites require entering three fields (number, expiration and CVV), while only 25 make a fourth mandatory (address and postal code). Most disturbing is that none of them bothers to verify the name printed on the plastic. The CVV calculation is done through a distributed attack using bots. The CVV consists of three digits, so the number of combinations never exceeds a thousand. Most services allow between six and ten attempts to enter card data, more than enough in this case. If for some reason the attacker has the CVV but not the expiration date, the process is even simpler, because card issuers do not deliver plastics with a duration exceeding sixty months.

According to the available data, the possibility of spreading the attack across hundreds of sites simultaneously reduces the waiting time to about six seconds. The researchers decided to go beyond online purchases with a stolen card number and conducted an experiment in which they used the information obtained from a plastic to create a fake account and transfer funds abroad. The process took 27 minutes, less than the time needed for the bank to block the transfer. To close, two interesting facts: On one hand, this type of attack affects Visa cards, since the MasterCard network detected distributed operations and deactivated them on the spot. And on the other, the researchers tried to contact the 36 most important sites, in an attempt to report their findings. Only eight made adjustments to their systems.

Access the full study (PDF):