Thursday, February 27, 2025
HomeCyber Security NewsCarding Action 2020 - Crooks selling/purchasing Compromised Card Data Arrested

Carding Action 2020 – Crooks selling/purchasing Compromised Card Data Arrested

Published on

SIEM as a Service

Follow Us on Google News

We, at GBhackers usually report instances where the bad guys have had the upper hand in cyber-security, but today we are glad to report that the good guys have had a minor victory.

Law enforcement agencies from Italy and Hungary supported by the UK and Europol carried out a targeted operation named Carding Action 2020, to catch fraudsters selling and purchasing compromised card details on websites selling stolen credit card data and dark web marketplaces.

The objective of the operation was to mitigate and prevent losses for financial institutions and card holders. The operation was carried out over a period of 3 months, with 90,000 pieces of card data analysed and approximately €40 million ($47 million) worth of losses averted.

Europol played a crucial role in facilitating the coordination of information between law enforcement authorities and private sector partners. Europol analysts and experts also supported this operation by analyzing large volumes of data and sharing their expertise in the field of payment card fraud.

All of the 90,000 pieces of card data analysed by Group-IB, the private sector partner, included data of cards compromised by phishing websites, end devices infected with banking Trojans, hijacked e-commerce websites and JS-sniffers.

This is not the first instance of Group-IB unearthing a cybersecurity crime. Some of the other crimes unearthed by Group-IB are Silence, hacking of e-commerce sites by 3 Indonesian hackers, and crimes of hacking group MoneyTaker are some of their noteworthy exploits.

“Cybercrime can affect all aspects of our daily life, from paying in the supermarket, transferring money to our friends to using online communication tools or Internet of Things devices at home. Cybercriminals can attack us in different ways and this requires a robust response not only from law enforcement, but also from the private sector,” said Edvardas Šileris, Head of Europol’s European Cybercrime Centre (EC3)

The increase of e-skimming attacks targeting merchant Point of Sale (PoS) machines and e-commerce merchants influenced the significant increase of prevented losses.

E-Skimming or Magecart is a cybersecurity hacking technique that steals information as the consumers enter the data into an online shopping website.

Stay safe and hope for more such victories!

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity, and hacking news updates.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Authorities Arrested Hacker Behind 90 Major Data Breaches Worldwide

Cybersecurity firm Group-IB, alongside the Royal Thai Police and Singapore Police Force, announced the...

Cisco Nexus Vulnerability Allows Attackers to Inject Malicious Commands

Cisco Systems has issued a critical security advisory for a newly disclosed command injection...

New Wi-Fi Jamming Attack Can Disable Specific Devices

A newly discovered Wi-Fi jamming technique enables attackers to selectively disconnect individual devices from...

GitLab Vulnerabilities Allow Attackers to Bypass Security and Run Arbitrary Scripts

GitLab has urgently released security updates to address multiple high-severity vulnerabilities in its platform...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Authorities Arrested Hacker Behind 90 Major Data Breaches Worldwide

Cybersecurity firm Group-IB, alongside the Royal Thai Police and Singapore Police Force, announced the...

Cisco Nexus Vulnerability Allows Attackers to Inject Malicious Commands

Cisco Systems has issued a critical security advisory for a newly disclosed command injection...

New Wi-Fi Jamming Attack Can Disable Specific Devices

A newly discovered Wi-Fi jamming technique enables attackers to selectively disconnect individual devices from...