MP3 Player Used to Steal ATM Codes

Mon Nov 20, 2006 5:50PM EST

See Comments (53)

Everyone laughed when the movie Firewall had the crook using an iPod to store bank secrets, but—ha ha ha—it turns out life is imitating art.

This story from the United Kingdom reveals how the scam worked: The crook would attach an MP3 player with recording capabilities to the phone line coming out of the ATM. (The ATMs in question were the freestanding ones like the type you see in convenience stores, not the ones built into walls.) By recording the tones the ATM transmitted to the bank, the crooks could later retrieve the recorder, translate the tones into digits, and reconstruct credit card numbers and expiration dates, which could then easily be turned into phony cards.

Maxwell Parsons managed to abscond with tens of thousands of dollars worth of purchases this way. Meanwhile, banks are careful to note that they have corrected the flaws that made this kind of exploit possible. (The story also notes that this scam nearly ruined the banking system in Malaysia, where it seems to have been pioneered.)

Still, there's a lesson here for the overly cautious: ATM scams are legendary (check out this example of how sophisticated they can be), but stand-alone ATMs are more vulnerable to attack because their connectivity cables are often exposed. If you're the paranoid type, stick with in-wall ATMs, especially if they're located indoors.

Comments on MP3 Player Used to Steal ATM Codes

Post a Comment

Join in the discussion. Here you'll see the comments in the order they were posted.

  • 6 Posted by wenow49 on Thu Sep 3, 2009 10:43PM EDT Report Abuse

    Always believe that if it seems impossible it has probably already been done!

  • 7 Posted by bexstheflyswimmer on Wed Jan 3, 2007 8:42AM EST Report Abuse

    yeah thanks for the info. now it will happen since the details are in the open. hahah

  • 10 Posted by jhanweck on Thu Sep 3, 2009 4:34PM EDT Report Abuse

    The banks obviously don't care about identity theft, otherwise they'd encrypt the information before it hits the phone line.

  • 11 Posted by ninamadelleine on Thu Sep 3, 2009 7:39PM EDT Report Abuse

    Is incredible how the things out there are getting worst. This news, shocked me... But, now I know how to prevent situation with this priceless info. Thanks a lot !!

  • 12 Posted by saltylakecity on Thu Sep 3, 2009 9:01PM EDT Report Abuse

    All this time I thought IPOD's were for playing music.

  • 13 Posted by saltylakecity on Thu Sep 3, 2009 9:01PM EDT Report Abuse

    I like how under the comment board it shows MP3's for sale!

  • 14 Posted by utgirl34 on Thu Sep 3, 2009 10:29PM EDT Report Abuse

    Why do you give the criminals all the information to try this, I don't use a ATM unless it is my banks.

  • 15 Posted by bundarmogi on Thu Sep 3, 2009 3:15PM EDT Report Abuse

    Hahaha....the story above is about how mp3 players can be used to record pin numbers etc. how ironic that the advert just slightly below is talking about selling MP3 players...lol

  • 16 Posted by alabamamikayla on Thu Sep 3, 2009 2:49PM EDT Report Abuse

    Yes im shocked but we shouldnt take ipods out of stores. Cause ipods can be used for good to like to listen to music and play games and watch movies. I have one and im not giving it up. I won't do all the bad stuff that some of the crooks would. But just because some people done this doesn't mean we will. So theres no reason to punish the good peoplefor what the bad has done.

  • 17 Posted by travlinman30 on Thu Sep 3, 2009 10:19PM EDT Report Abuse

    I wonder if you can download tunes to your Pod while you're doing the ATM hack? I like to multitask.

  • 18 Posted by libstooges on Thu Sep 3, 2009 6:50PM EDT Report Abuse

    If crime didn't pay - there would not be so many people involved in it.

  • 19 Posted by bcasecomputers on Thu Sep 3, 2009 3:03PM EDT Report Abuse

    wow awsome.... To make it record simply use a Linux port for the ipod... very easy install.... that you can create a tone box and use the line from the atm... They should have been using random digits or going over a network not through a phone line..They deserve this hack.

  • 20 Posted by kelpasc08 on Thu Sep 3, 2009 4:49PM EDT Report Abuse

    wow that's amazing i didn't think you could do that from an ipod..

  • 21 Posted by davesink2 on Thu Sep 3, 2009 3:37PM EDT Report Abuse

    To those scolding Yahoo news for posting how the scam is perpetrated: have actually read the story? "...Meanwhile, banks are careful to note that they have corrected the flaws that made this kind of exploit possible."

  • 22 Posted by louisiana_hot_momma on Thu Sep 3, 2009 6:57PM EDT Report Abuse

    I think that is so stupid........ the ATM is supposed to have cameras attached to it and also the bank has cameras, even if it only took these people a split second to attach this stuff, with the cameras in place it shouldn't have taken the security people that long to unattach it. What are the cameras in place for...

  • 23 Posted by maxgain2001 on Thu Sep 3, 2009 7:12PM EDT Report Abuse

    Nice idea, but ipods and most other MP3 "PLAYERS" don't record, they do act like drives and can be written to, but audio recording they do not do.

  • 24 Posted by kenfaby on Thu Sep 3, 2009 4:49PM EDT Report Abuse

    The article explains how the PIN was discovered but not how the account number was stolen. The PIN without the account is useless.

  • 25 Posted by kenfaby on Thu Sep 3, 2009 4:49PM EDT Report Abuse

    The article explains how the PIN was discovered but not how the account number was stolen. The PIN without the account is useless.

Post a Comment


My Tech

Please enable your browser's cookies to activate the My Tech column.

Also on Yahoo! Tech

Computers Home Office Wi-Fi & Networking Phones & PDAs Cameras & Camcorders TV & Home Theater Portable Audio
 

Question and Answer content at Yahoo! Tech is written by Yahoo! users at Yahoo! Answers. Yahoo! does not evaluate or guarantee the accuracy of any Yahoo! Answers content. For more information, read the Full Disclaimer.

Opinions expressed by the Advisors are their own and do not necessarily reflect the views of Yahoo! Inc. Yahoo! receives no compensation from any manufacturer or distributor nor does it compensate any Advisor for the coverage of any product or service in any Advisor's content.