Romanian Hackers Steal $3 Million From Subway Sandwich Chain
- Posted on December 22, 2011 at 10:48pm by
Liz Klimas
- Print »
- Email »
Since 2008, hackers from Romania have been logging customer information and virtually pilfered $3 million from customers of Subway sandwich shops as well as some small retailers.
Gizmodo reports that 150 different Subway stores and at least 50 retail shops were affected with the hackers collecting information from more than 80,000 customers. Ars Technica reports that the hackers committed the crime without too much effort, relatively speaking:
“This is the crime of the future,” said Dave Marcus, director of security research and communications at McAfee Labs in an interview with Ars. Instead of coming in with guns and robbing the till, he said, criminals can target small businesses, “root them from across the planet, and steal digitally.”
The tools used in the crime are widely available on the Internet for anyone willing to take the risks, and small businesses’ generally poor security practices and reliance on common, inexpensive software packages to run their operations makes them easy pickings for large-scale scams like this one, Marcus said.
Ars Technica goes on to report Konrad Fellmann, audit and compliance manager for SecureState, says that in most situations the ability to gain access to credit card information in the way these hackers did wouldn’t be possible. Remote access is banned for systems storing credit card information by the PCI Security Standards Council. But for smaller businesses that don’t store credit card info, this rule does not apply. Subway should franchises should have abided by the PCI rule but Evan Schuman, editor of retail technology trade site StorefrontBacktalk, said that franchise owners often “directly and blatantly disregarded” the policy, according to Ars Technica.
Some of the data, Ars Technica reports, was used to make fake credit cards. Find more details on how the hackers collected the information here.



















Submitting your tip... please wait!
garbagecanlogic
Posted on December 23, 2011 at 2:23pmIf subway had $3 mil to give away, why did it not have a reliable software program?
The U.S. Out Of The U.N.
Report Post »The U.N. Out Of The U.S.
RedDawn-2012
Posted on December 23, 2011 at 10:23pmHa! Read much? Subway didn’t lose the money . . . it’s CUSTOMERS lost the money via credit card fraud.
Report Post »Ghandi was a Republican
Posted on December 23, 2011 at 9:28amWE have a Federal Government who cannot protect us !
Report Post »Ruler4You
Posted on December 23, 2011 at 12:45pmLook, IMHBLO, the government KNEW this was the “crime of the future.”
How can I say that? Because I knew it. Any moron could have told you this was where we were going. And again IMHBLO, the above statement ‘this is the crime of the future…’ was THE statement they have been waiting to make, for a long time. Now, we can begin promoting a cashless society in earnest. Business, is at stake.
Because you can bet your LAST nickle they aren’t going to embrace wide spread and always effective encryption of YOUR DATA. Ever.
This may be the ‘crime of the future’ but loss of and manipulation of YOUR DATA is the BUSINESS of the future. An industry that is just now being planted.
Software companies “could” prevent this. But next years sales may be affected. Computers wouldn’t risk being destroyed by viruses. And that would affect new computer sales. Insurance companies ANY insurance company could offer “identity protection” to ALL customers. Not just some software company whose entire business model is based on the failure of secure identities to drive customers their way.
Sounds like a conflict of interest to me.
No, we are being driven, herded like mindless sheep all over the place to keep us guessing and off balance. Because THAT “IS” economic stimulation.
Report Post »TRUTHandFREEDOM
Posted on December 23, 2011 at 6:59amThat last paragraph really needs a rewrite.
Report Post »RugDog
Posted on December 23, 2011 at 2:56amOf course its the kenyan obamas fault. Really.
Report Post »smokey888x2
Posted on December 23, 2011 at 12:42amSide question: Why doesn’t the United States build an intra-country stand-by internet system?
Concerning story: While we’re in this prone-mode of not being able to stop a lot of this theivery at this time, why don’t we up the prison time to 20 or 25 years with a mandatory serving time of 95%?
Report Post »last frontier
Posted on December 23, 2011 at 12:25amThe Government loves this stuff, it gives them one more reason to take our rights and privacy away.
Report Post »Endstatism
Posted on December 23, 2011 at 12:10amOne way to break all of the hacking, financial fraud and theft would be to pass a law that states if caught you will not only have to serve 25 years in prison, you will have to pay everyone you ripped off or else you remain in jail. I am of the opinion that federal law enforcement is not taking cyber crimes seriously. The software and the experts are there to track and pinpoint hackers who are fleecing businesses and individuals.
Report Post »dnewton
Posted on December 23, 2011 at 12:23amI have always suspected that nobody wants strict laws against hacking because they are afraid that the first one caught will be their kid. If the malefactor is not my kid… hang em high.
Report Post »saintjock
Posted on December 22, 2011 at 11:44pmYes toasted please.
Report Post »Eric_The_Red_State
Posted on December 22, 2011 at 11:26pmJared…. you got some ‘splainin to do……
Report Post »HorseCrazy
Posted on December 22, 2011 at 11:22pmoh sure it’s subways fault these foreign hackers stole info. these dang stores are franchises and sometimes small potatos depending on the location and can’t afford to keep up with this garbage. I have an idea how about the cybercrimes unit of the fbi actually do something. just a thought they have a ginormous budget and don’t do squat. I reported a fraud ring being perpetrated on my rental business and it’s been 8 months and still yet to hear back from them. loads of money lost by innocent folks and no phone call no email no nada
Report Post »AMERICA4EVER
Posted on December 23, 2011 at 1:00amFunny, when we carried just cash, we never had this problem. But I guess if you did that now, they would just knock you in the head a take it.
Report Post »NoLongerNonPlussed
Posted on December 22, 2011 at 11:18pmThese are not the droids that you want.
Report Post »There was no crime here.
Disregard this non information.
There was no money theft.
There was no stealing involved.
Computer users from another system simply copied what the Fed did…they created virtual digits out of the ether. Happy Christmas hackers.
packsack54
Posted on December 22, 2011 at 11:16pmI keep tell my kid quit using debt card and credit card. Pay with cah you will not over spend and get ripped off. A leson for the brainless and clueless people, just another bunch of FBI’s.
Report Post »MEANS2RESIST
Posted on December 23, 2011 at 1:19amAnd then there’s Chase Bank promoting pay by your smart phone….the ad on TV where they all eat lunch then transfer the their share of $$ for the bill into the one girls bank acct by smart phone….not too smart in my opinion…These braindead kids will fall for anything these days….
Report Post »AB5r
Posted on December 22, 2011 at 11:08pmWouldn’t someone cancel their card after the first unauthorized charge?
Report Post »Stoic one
Posted on December 22, 2011 at 10:56pmNow that is disturbing…non compliance, so now I know where not to buy with plastic.
Report Post »Snowleopard {gallery of cat folks}
Posted on December 22, 2011 at 11:01pmIndeed, and I have to wonder which band of Obama’s radical friends is doing this.
Report Post »superbyelich
Posted on December 22, 2011 at 11:13pm@snowleopard
So are we now blaming everything bad that happens on Obama like they blamed everything on Bush? Wow… that’s just a weird comment.
Report Post »barber2
Posted on December 22, 2011 at 11:27pmSnow: probably the Lefty, Wiki-Leaks Internationalists…all part of the anarchistic Lefty “youth” Movement… which means the young are taking themselves to live in an “every man for himself/ there are no rules/ Dark Ages/ Jungle / Survival of the Fittest ” New World. Sounds like something from a 1950′s Science Fiction movie. Nasty place… Hope the decent young are able to fight these youthful, politically whacked but active twisted souls , who seem to have the media/ Democrats fighting FOR them , while the decent youths are out seeking jobs and doing , innocently, what decent people do. These “average ” Americans are doing what they normally do while silently , under the radar , dominant media protected, others are busy undermining the very freedoms upon which this country and constitution were founded.
Report Post »barber2
Posted on December 22, 2011 at 11:40pmSUPER: Ever since the Democrats rooled out rhe Affordable Housing Act I( Big Lie ), all Americans need to start being suspitious and, yes, blaming the Democrats for the disaster they have caused. The Democrats started the Blame Bush from the Genral Be-tray-us / I hate the Iragui War rhetoric. Then they stretched it into Blame Bush for evertything . That made it real easy for them to gloss over the phony/ vote buying “Afforadable Housing Act, ” based on playing the old Discrimination Card, into Blame Bush for the economy mess that the Democrats caused by their crazy, Lefty, discrimination against the “poor” pressures which ensured that people got home loans without being “ vetted ” for their ability to re -pay those loans. Sort of like how the mysterious Good Daddy/ He Voted Present candidate Obama got elected before being vetted for being presidential material . The basic process of being vetted became an accusation of ” racism/ discrimination” which is how we wound up in the colossal economic mess we are now in. Standards ? Requirements? Lessen risk ? Bring them back. Along with manners and a sense of shame .
Report Post »superbyelich
Posted on January 22, 2012 at 11:15amBARBER2: Actually they blamed bush for way more than just General “Betray US” It was going on way before that, he was even blamed for a natural disaster “Katrina.” So to me blaming Romanian hackers stealing money from Subway on Obama just as absurd.
Report Post »