Hong Kong News

Nonpartisan, Noncommercial, unconstrained.
Friday, Mar 29, 2024

400,000 sets of stolen Hong Kong payment card data for sale on dark web: study

400,000 sets of stolen Hong Kong payment card data for sale on dark web: study

Hong Kong has third highest number of stolen credit, debit card details up for sale of 140 places analysed, according to cybersecurity firm.

Nearly 10 per cent of the 4.5 million sets of stolen payment card details offered for sale on sections of the dark web were fraudulently obtained in Hong Kong, according to a new cybersecurity report.

The research by Panama-based internet security firm NordVPN ranked the city third out of the 140 places analysed last month for the prevalence of stolen credit and debit card data advertised on the black market, with 399,537 instances recorded.

Stolen details originating from Hong Kong and the Philippines commanded the highest price per card of almost US$20, the study found.

NordVPN’s chief technology officer, Marijus Briedis, said that Hong Kong’s status as a “densely populated key financial centre” made it a popular target for criminals.

“There’s a disproportionately high number of cards available [in Hong Kong] considering the population size, so there’s a much higher chance of any given card being on the [dark web] databases,” he said.

The United States topped the list with 1,561,739 sets of stolen card data up for sale, followed by Australia with 419,806, both of which have far bigger populations than Hong Kong’s 7.5 million.

The study published on Wednesday analysed 20 databases on the dark web offering a total of 4,478,908 sets of stolen details for sale.

Briedis said 99 per cent of the stolen card details from Hong Kong involved non-refundable types, reflecting many residents’ preference for such cards compared with the rest of the world.

Hackers might target places with more non-refundable cards given their owners were not allowed to be reimbursed by card issuers for the scammed or stolen money.

But he said that tendency did not mean that Hong Kong’s card security was poor.

“If a user’s bank has a multi-factor authentication, fraud detection or other AI-based [artificial intelligence] security measures in place – he can stay protected even if the card was ‘brute-forced’,” he said, referring to the use of computers to crack passcodes.

Researchers also calculated so-called risk indexes, reflecting how likely it is that payment card details from particular places will end up on the dark web. Risk factors include the per capita figure for cards from a jurisdiction already on the databases, how many cards are in use there, and the proportion of those that are non-refundable.

Hong Kong was found to be at most risk with a score of one, followed by Australia and New Zealand. The risk index is graded from zero to one, the latter being the most severe.

Hackers use software to make thousands of guesses on payment card passcodes every second.


More than half of all the stolen Hong Kong credit cards were issued by Visa, followed by Mastercard and then American Express.

Explaining how hackers used computers to guess passcodes, he said: “First it tries 000000, then 000001, then 000002, and so on until it gets it right.

“Being a computer, it can make thousands of guesses a second. After a hacker has successfully brute-forced a card number they put it on a dark web for sell for other criminals to buy and misuse them.”

The research also showed that the average selling price of card details from Hong Kong is US$19.84, higher than the overall average of US$9.7.

Briedis said: “This is probably linked to the perceptions of Hong Kong’s financial connection that make it seems like you would get a better return on the cards.”

He said there was an upwards trend of payment card details being put on the dark web since 2014, adding the 20 databases featured in the study were only the tip of the iceberg.

“The answer is that hackers can easily make a lot of money,” he said. “Even if a card costs only US$10 on average, a hacker can make US$40 million by selling a single database, like the one that we analysed.”

Briedis suggested that cardholders keep track of any irregular transactions in their banking statements.

“Nobody is safe from it. The cards are brute-forced, the technology hackers use to do it is only getting better. So it is very important for users to keep track of their statements regularly,” he said.

Francis Fong Po-kiu, honorary president of the Hong Kong Information Technology Federation, suggested that locals possessing a large number of credit cards might be behind the city’s high ranking in the study.

He warned that some shopping websites did not provide “3D Secure” authentication, which offered an extra verification step before customers made their payments.

The Hong Kong Monetary Authority said it required banks to implement a “robust fraud monitoring mechanism” to spot suspicious credit card activity promptly and validate transactions with the cardholder before payment authorisation.

“For card-not-present transactions, banks are required to send timely notifications to customers to enable them to detect unauthorised transactions on a timely basis,” its spokesman said.

“Generally speaking, if cardholders have not acted fraudulently or with gross negligence, they will not be liable for losses arising from unauthorised transactions.”

Newsletter

Related Articles

Hong Kong News
0:00
0:00
Close
It's always the people with the dirty hands pointing their fingers
Paper straws found to contain long-lasting and potentially toxic chemicals - study
FTX's Bankman-Fried headed for jail after judge revokes bail
Blackrock gets half a trillion dollar deal to rebuild Ukraine
Steve Jobs' Son Launches Venture Capital Firm With $200 Million For Cancer Treatments
Google reshuffles Assistant unit, lays off some staffers, to 'supercharge' products with A.I.
End of Viagra? FDA approved a gel against erectile dysfunction
UK sanctions Russians judges over dual British national Kara-Murza's trial
US restricts visa-free travel for Hungarian passport holders because of security concerns
America's First New Nuclear Reactor in Nearly Seven Years Begins Operations
Southeast Asia moves closer to economic unity with new regional payments system
Political leader from South Africa, Julius Malema, led violent racist chants at a massive rally on Saturday
Today Hunter Biden’s best friend and business associate, Devon Archer, testified that Joe Biden met in Georgetown with Russian Moscow Mayor's Wife Yelena Baturina who later paid Hunter Biden $3.5 million in so called “consulting fees”
'I am not your servant': IndiGo crew member, passenger get into row over airline meal
Singapore Carries Out First Execution of a Woman in Two Decades Amid Capital Punishment Debate
Spanish Citizenship Granted to Iranian chess player who removed hijab
US Senate Republican Mitch McConnell freezes up, leaves press conference
Speaker McCarthy says the United States House of Representatives is getting ready to impeach Joe Biden.
San Francisco car crash
This camera man is a genius
3D ad in front of Burj Khalifa
Next level gaming
BMW driver…
Google testing journalism AI. We are doing it already 2 years, and without Google biased propoganda and manipulated censorship
Unlike illegal imigrants coming by boats - US Citizens Will Need Visa To Travel To Europe in 2024
Musk announces Twitter name and logo change to X.com
The politician and the journalist lost control and started fighting on live broadcast.
The future of sports
Unveiling the Black Hole: The Mysterious Fate of EU's Aid to Ukraine
Farewell to a Music Titan: Tony Bennett, Renowned Jazz and Pop Vocalist, Passes Away at 96
Alarming Behavior Among Florida's Sharks Raises Concerns Over Possible Cocaine Exposure
Transgender Exclusion in Miss Italy Stirs Controversy Amidst Changing Global Beauty Pageant Landscape
Joe Biden admitted, in his own words, that he delivered what he promised in exchange for the $10 million bribe he received from the Ukraine Oil Company.
TikTok Takes On Spotify And Apple, Launches Own Music Service
Global Trend: Using Anti-Fake News Laws as Censorship Tools - A Deep Dive into Tunisia's Scenario
Arresting Putin During South African Visit Would Equate to War Declaration, Asserts President Ramaphosa
Hacktivist Collective Anonymous Launches 'Project Disclosure' to Unearth Information on UFOs and ETIs
Typo sends millions of US military emails to Russian ally Mali
Server Arrested For Theft After Refusing To Pay A Table's $100 Restaurant Bill When They Dined & Dashed
The Changing Face of Europe: How Mass Migration is Reshaping the Political Landscape
China Urges EU to Clarify Strategic Partnership Amid Trade Tensions
The Last Pour: Anchor Brewing, America's Pioneer Craft Brewer, Closes After 127 Years
Democracy not: EU's Digital Commissioner Considers Shutting Down Social Media Platforms Amid Social Unrest
Sarah Silverman and Renowned Authors Lodge Copyright Infringement Case Against OpenAI and Meta
Why Do Tech Executives Support Kennedy Jr.?
The New York Times Announces Closure of its Sports Section in Favor of The Athletic
BBC Anchor Huw Edwards Hospitalized Amid Child Sex Abuse Allegations, Family Confirms
Florida Attorney General requests Meta CEO's testimony on company's platforms' alleged facilitation of illicit activities
The Distorted Mirror of actual approval ratings: Examining the True Threat to Democracy Beyond the Persona of Putin
40,000 child slaves in Congo are forced to work in cobalt mines so we can drive electric cars.
×