Future attack scenarios against ATM authentication systems

frogboy

In memoriam 1961-2018
Thread author
Verified
Top Poster
Well-known
Jun 9, 2013
6,720
A lot has already been said about current cyber threats facing the owners of ATMs. The reason behind the ever-growing number of attacks on these devices is simple: the overall level of security of modern ATMs often makes them the easiest and fastest way for fraudsters to access the bank’s money. Naturally, the banking industry is reacting to these attacks by implementing a range of security measures, but the threat landscape is continually evolving. In order to prepare banks for what they should expect to see from criminals in the near future, we’ve prepared an overview report of future cyberthreats to ATMs. The report will – we hope – help the industry to better prepare for a new generation of attack tools and techniques.

The report comprises two papers in which we analyze all existing methods of authentication used in ATMs and those expected to be used in the near future, including: contactless authentication through NFC, one-time password authentication and biometric authentication systems, as well as potential vectors of attacks using malware, through to network attacks and attacks on hardware components.

We looked into what is going on underground around these technologies and were surprised to discover that there are twelve manufacturers out there that are already offering fake fingerprint scanners, otherwise known as biometric skimmers. There are also at least three other vendors researching devices that will be able to illegally obtain data from palm vein and iris recognition systems.

This is a major trend, because the problem with biometrics is that, unlike passwords or pin codes which can be easily modified in the event of compromise, it is impossible to change your fingerprint or iris image. Thus if your data is compromised once, it won’t be safe to use in the future. That is why it is extremely important to keep such data secure and transmit it in a secure way. Biometric data is also recorded in modern passports – called e-passports – and visas. So, if an attacker steals an e-passport, they not only steal the document, but also that person’s biometric data. As a result they steal a person’s identity.

The biometric data can also be accessed by criminals as a result of hacking into a bank’s infrastructure, which is also a major issue: if you lose the biometric database of your clients it won’t be possible to solve this problem just by recalling compromised payment cards. This is an unrecoverable loss and thus it is a kind of threat that the industry has never experienced before.

In general, network-based attacks against ATMs will be a headache for the security personnel of financial organizations in the coming years simply because, based on our penetration testing experience, the network infrastructure of a bank is very often built in a way that a hacker can exploit to gain access and take control of some critical parts of the network, including the network of ATMs. And this situation is not going to change any time soon, due to many reasons, one of which is the sheer size of financial organizations’ networks and the time-consuming and expensive task of upgrading them.

Nevertheless, by publishing this report we’d like to draw attention to the problem of ATM security now and in the near future, and to speed up the development of a truly secure ecosystem around these devices.

Read the full report here

Read the description of attacks here

Full Article. https://securelist.com/analysis/pub...scenarios-against-atm-authentication-systems/
 

Myriad

Level 7
Verified
Well-known
May 22, 2016
349
Good article , good post !

Hard to believe , but vast numbers of ATMs across the globe are still running WindowsXP ( embedded ) with very expensive contract support from M$ , I reckon .

The other day I read about the latest ultra-thin card-skimmers which will fit inside the card reader slot !
So no more need for the scamsters to use a false front .
( I'm sorry but I can't find the link anymore )

It is never going to stop , regardless of any measures banks and ATM operators take .

When asked why he wouldn't quit robbing banks , John Dillinger said :
" Because it's where they keep the money ".
 
Last edited:

Myriad

Level 7
Verified
Well-known
May 22, 2016
349
You would think that with billion's of dollars of profit that banks make every year (at least here in Australia), that they would invest in modern technology and upgrade their atm's.:mad:

It's because the cost of changing terrifies them .
We are talking about starting an entire new system from scratch , on a nationwide or probably worldwide level.

The idea of somehow "porting" the existing system to a modern operating OS ( and the hardware to run it on ) is a total non-starter.
For one thing , it is all 32-bit !
And how , and when could they ever do the massive switchover ?

I don't know how the banks are doing in Australia , but US and European banks are being given a vicious thrashing by regulators ,
over their dirty deeds that led to the 2008 crisis.
And the penalties are in billions also ; there was another one this past week in the EU.

I suspect they couldn't afford the cost , or the security risk of a new system ,no matter how desperately they need modern technology .
 
Last edited:

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
ATM's should also focus on hardware protection in such full blown with different techniques.

Nowadays skimming of cards is so easy without any detection immediately. Also the problem occur when the time skimming already attached on ATM.

Software detection must also enforce so that the user is aware when ATM is infected.
 
  • Like
Reactions: DardiM

CMLew

Level 23
Verified
Well-known
Oct 30, 2015
1,251
I would say it's fairly common for large organization to have delays in upgrading especially software. IMHO government agencies, banks, and many others would most likely wanted to upgrade the software, but hampered by the hardware incompatiblity and vice versa.

Heard from an acquaintance that in certain countries (not wish to name which), their immigration department is still using Win XP due to hardware/equipment issue. And that includes those in immigration counters. :eek: and so does ATM and many others.
 
  • Like
Reactions: DardiM
L

LabZero

Unfortunately also in my country there are still ATMs with Windows XP.
It is logical that, keeping active ATMs based on operating systems without support, is a serious lack of security, which could give the opportunity to criminals to exploit unpatched flaws!

Another serious vulnerability is the exposure of the ATM on the internet, often by enabling not necessary services such as remote support or ftp services.
Still about 95% of the ATMs in the megastores is connected to the internet via Dial up!
Maybe some dialer is still in circulation...:D
 
  • Like
Reactions: DardiM and frogboy

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top