Crime

Romanian Hackers Steal $3 Million From Subway Sandwich Chain

$3 Million Stolen From Credit Cards in Subway HackSince 2008, hackers from Romania have been logging customer information and virtually pilfered $3 million from customers of Subway sandwich shops as well as some small retailers.

Gizmodo reports that 150 different Subway stores and at least 50 retail shops were affected with the hackers collecting information from more than 80,000 customers. Ars Technica reports that the hackers committed the crime without too much effort, relatively speaking:

“This is the crime of the future,” said Dave Marcus, director of security research and communications at McAfee Labs in an interview with Ars. Instead of coming in with guns and robbing the till, he said, criminals can target small businesses, “root them from across the planet, and steal digitally.”

The tools used in the crime are widely available on the Internet for anyone willing to take the risks, and small businesses’ generally poor security practices and reliance on common, inexpensive software packages to run their operations makes them easy pickings for large-scale scams like this one, Marcus said.

Ars Technica goes on to report Konrad Fellmann, audit and compliance manager for SecureState, says that in most situations the ability to gain access to credit card information in the way these hackers did wouldn’t be possible. Remote access is banned for systems storing credit card information by the PCI Security Standards Council. But for smaller businesses that don’t store credit card info, this rule does not apply. Subway should franchises should have abided by the PCI rule but Evan Schuman, editor of retail technology trade site StorefrontBacktalk, said that franchise owners often “directly and blatantly disregarded” the policy, according to Ars Technica.

Some of the data, Ars Technica reports, was used to make fake credit cards. Find more details on how the hackers collected the information here.

Comments (25)

  • garbagecanlogic
    Posted on December 23, 2011 at 2:23pm

    If subway had $3 mil to give away, why did it not have a reliable software program?

    The U.S. Out Of The U.N.
    The U.N. Out Of The U.S.

    Report Post »  
    • RedDawn-2012
      Posted on December 23, 2011 at 10:23pm

      Ha! Read much? Subway didn’t lose the money . . . it’s CUSTOMERS lost the money via credit card fraud.

      Report Post » RedDawn-2012  
  • Ghandi was a Republican
    Posted on December 23, 2011 at 9:28am

    WE have a Federal Government who cannot protect us !

    Report Post » Ghandi was a Republican  
    • Ruler4You
      Posted on December 23, 2011 at 12:45pm

      Look, IMHBLO, the government KNEW this was the “crime of the future.”

      How can I say that? Because I knew it. Any moron could have told you this was where we were going. And again IMHBLO, the above statement ‘this is the crime of the future…’ was THE statement they have been waiting to make, for a long time. Now, we can begin promoting a cashless society in earnest. Business, is at stake.
      Because you can bet your LAST nickle they aren’t going to embrace wide spread and always effective encryption of YOUR DATA. Ever.

      This may be the ‘crime of the future’ but loss of and manipulation of YOUR DATA is the BUSINESS of the future. An industry that is just now being planted.

      Software companies “could” prevent this. But next years sales may be affected. Computers wouldn’t risk being destroyed by viruses. And that would affect new computer sales. Insurance companies ANY insurance company could offer “identity protection” to ALL customers. Not just some software company whose entire business model is based on the failure of secure identities to drive customers their way.
      Sounds like a conflict of interest to me.

      No, we are being driven, herded like mindless sheep all over the place to keep us guessing and off balance. Because THAT “IS” economic stimulation.

      Report Post » Ruler4You  
  • TRUTHandFREEDOM
    Posted on December 23, 2011 at 6:59am

    That last paragraph really needs a rewrite.

    Report Post »  
  • RugDog
    Posted on December 23, 2011 at 2:56am

    Of course its the kenyan obamas fault. Really.

    Report Post » RugDog  
  • smokey888x2
    Posted on December 23, 2011 at 12:42am

    Side question: Why doesn’t the United States build an intra-country stand-by internet system?

    Concerning story: While we’re in this prone-mode of not being able to stop a lot of this theivery at this time, why don’t we up the prison time to 20 or 25 years with a mandatory serving time of 95%?

    Report Post » smokey888x2  
  • last frontier
    Posted on December 23, 2011 at 12:25am

    The Government loves this stuff, it gives them one more reason to take our rights and privacy away.

    Report Post » last frontier  
  • Endstatism
    Posted on December 23, 2011 at 12:10am

    One way to break all of the hacking, financial fraud and theft would be to pass a law that states if caught you will not only have to serve 25 years in prison, you will have to pay everyone you ripped off or else you remain in jail. I am of the opinion that federal law enforcement is not taking cyber crimes seriously. The software and the experts are there to track and pinpoint hackers who are fleecing businesses and individuals.

    Report Post » Endstatism  
    • dnewton
      Posted on December 23, 2011 at 12:23am

      I have always suspected that nobody wants strict laws against hacking because they are afraid that the first one caught will be their kid. If the malefactor is not my kid… hang em high.

      Report Post »  
  • saintjock
    Posted on December 22, 2011 at 11:44pm

    Yes toasted please.

    Report Post » saintjock  
  • Eric_The_Red_State
    Posted on December 22, 2011 at 11:26pm

    Jared…. you got some ‘splainin to do……

    Report Post » Eric_The_Red_State  
  • HorseCrazy
    Posted on December 22, 2011 at 11:22pm

    oh sure it’s subways fault these foreign hackers stole info. these dang stores are franchises and sometimes small potatos depending on the location and can’t afford to keep up with this garbage. I have an idea how about the cybercrimes unit of the fbi actually do something. just a thought they have a ginormous budget and don’t do squat. I reported a fraud ring being perpetrated on my rental business and it’s been 8 months and still yet to hear back from them. loads of money lost by innocent folks and no phone call no email no nada

    Report Post »  
    • AMERICA4EVER
      Posted on December 23, 2011 at 1:00am

      Funny, when we carried just cash, we never had this problem. But I guess if you did that now, they would just knock you in the head a take it.

      Report Post »  
  • NoLongerNonPlussed
    Posted on December 22, 2011 at 11:18pm

    These are not the droids that you want.
    There was no crime here.
    Disregard this non information.
    There was no money theft.
    There was no stealing involved.
    Computer users from another system simply copied what the Fed did…they created virtual digits out of the ether. Happy Christmas hackers.

    Report Post » NoLongerNonPlussed  
  • packsack54
    Posted on December 22, 2011 at 11:16pm

    I keep tell my kid quit using debt card and credit card. Pay with cah you will not over spend and get ripped off. A leson for the brainless and clueless people, just another bunch of FBI’s.

    Report Post »  
    • MEANS2RESIST
      Posted on December 23, 2011 at 1:19am

      And then there’s Chase Bank promoting pay by your smart phone….the ad on TV where they all eat lunch then transfer the their share of $$ for the bill into the one girls bank acct by smart phone….not too smart in my opinion…These braindead kids will fall for anything these days….

      Report Post » MEANS2RESIST  
  • AB5r
    Posted on December 22, 2011 at 11:08pm

    Wouldn’t someone cancel their card after the first unauthorized charge?

    Report Post » AB5r  
  • Stoic one
    Posted on December 22, 2011 at 10:56pm

    Now that is disturbing…non compliance, so now I know where not to buy with plastic.

    Report Post » Stoic one  
    • Snowleopard {gallery of cat folks}
      Posted on December 22, 2011 at 11:01pm

      Indeed, and I have to wonder which band of Obama’s radical friends is doing this.

      Report Post » Snowleopard {gallery of cat folks}  
    • superbyelich
      Posted on December 22, 2011 at 11:13pm

      @snowleopard

      So are we now blaming everything bad that happens on Obama like they blamed everything on Bush? Wow… that’s just a weird comment.

      Report Post » superbyelich  
    • barber2
      Posted on December 22, 2011 at 11:27pm

      Snow: probably the Lefty, Wiki-Leaks Internationalists…all part of the anarchistic Lefty “youth” Movement… which means the young are taking themselves to live in an “every man for himself/ there are no rules/ Dark Ages/ Jungle / Survival of the Fittest ” New World. Sounds like something from a 1950′s Science Fiction movie. Nasty place… Hope the decent young are able to fight these youthful, politically whacked but active twisted souls , who seem to have the media/ Democrats fighting FOR them , while the decent youths are out seeking jobs and doing , innocently, what decent people do. These “average ” Americans are doing what they normally do while silently , under the radar , dominant media protected, others are busy undermining the very freedoms upon which this country and constitution were founded.

      Report Post »  
    • barber2
      Posted on December 22, 2011 at 11:40pm

      SUPER: Ever since the Democrats rooled out rhe Affordable Housing Act I( Big Lie ), all Americans need to start being suspitious and, yes, blaming the Democrats for the disaster they have caused. The Democrats started the Blame Bush from the Genral Be-tray-us / I hate the Iragui War rhetoric. Then they stretched it into Blame Bush for evertything . That made it real easy for them to gloss over the phony/ vote buying “Afforadable Housing Act, ” based on playing the old Discrimination Card, into Blame Bush for the economy mess that the Democrats caused by their crazy, Lefty, discrimination against the “poor” pressures which ensured that people got home loans without being “ vetted ” for their ability to re -pay those loans. Sort of like how the mysterious Good Daddy/ He Voted Present candidate Obama got elected before being vetted for being presidential material . The basic process of being vetted became an accusation of ” racism/ discrimination” which is how we wound up in the colossal economic mess we are now in. Standards ? Requirements? Lessen risk ? Bring them back. Along with manners and a sense of shame .

      Report Post »  
    • superbyelich
      Posted on January 22, 2012 at 11:15am

      BARBER2: Actually they blamed bush for way more than just General “Betray US” It was going on way before that, he was even blamed for a natural disaster “Katrina.” So to me blaming Romanian hackers stealing money from Subway on Obama just as absurd.

      Report Post » superbyelich  

Sign In To Post Comments! Sign In