Tag Archive for: AmEx

This gizmo knows your Amex card number before you’ve received it

A device built by legendary hacker Samy Kamkar calls into question the security of payment cards as the U.S. continues to grapples with card fraud.

Kamkar’s device, nicknamed MagSpoof, is about the size of a U.S. quarter, and it’s safe to say it would be a fraudster’s dream.

MagSpoof can predict what a new American Express card number will be based on a canceled card’s number. The new expiration date can also be predicted based on when the replacement card was requested.

It can also trick point-of-sale readers into accepting payment from cards that are supposed to have a microchip with advanced cryptographic capabilities designed to deter fraud, a system known as chip-and-PIN, but do not.

To read this article in full or to leave a comment, please click here

Network World Security

“Funded hacktivism” or cyber-terrorists, AmEx attackers have big bankroll

The “cyber-fighters of Izz ad-Din al-Qassam” took American Express down for two hours yesterday afternoon.

On March 28, American Express’ website went offline for at least two hours during a distributed denial of service attack. A group calling itself “the cyber-fighters of Izz ad-Din al-Qassam” claimed responsibility for the attack, which began at about 3:00pm Eastern Time.

In a statement, an American Express spokesperson said, “Our site experienced a distributed-denial-of-service (DDoS) attack for about two hours on Thursday afternoon…We experienced intermittent slowing on our website that would have disrupted customers’ ability to access their account information. We had a plan in place to defend against a potential attack and have taken steps to minimize ongoing customer impact.”

The American Express DDoS is part of a new wave of attacks started two weeks ago by the Izz ad-Din al-Qassam group, which launched a larger campaign targeting US financial institutions that began last September. The group’s alleged goal is to force the take-down of an offensive YouTube video—or extract an ongoing price from American banks as long as the video stays up, which could be indefinitely.

Read 15 remaining paragraphs | Comments


Ars Technica » Technology Lab