Security Awareness: The Dangers of Using ATM How To Protect Yourself?
Security Awareness: The Dangers of Using ATM How To Protect Yourself?
The purpose of this presentation is to make the audience aware of the dangers of
using ATMs and how to protect from ATM Frauds
In no case the reader should use any techniques presented to perform ATM Frauds.
It is for awareness ONLY and the Author disclaims of any liability thereafter
• Remote Monitoring
General Practices - Video Surveillance
• Skimming Devices
ATM Fraud Techniques – Card Theft
Skimming Devices:
ATM Fraud Techniques – Skimming
Devices
Skimming Devices:
ATM Fraud Techniques – Preventing
Skimming
• Attentiveness of ATM consumers, branch
personnel or ATM Service technician
• Visual clues – presence of adhesive tape
residue near or on card reader
• Therefore, awareness for consumers, Branch
personnel and ATM service Technician
ATM Fraud Techniques – Preventing
Skimming
• Use Anti-skimming solutions:
– Control speed of the movement of the card or
– Intentional erratic movement of the card
during card insertion and return by the
motorized card reader – will confuse most
skimming devices
– Jitter techniques incorporated into some
newer card reader designs
ATM Fraud Techniques – Preventing
Skimming
• Use Anti-skimming solutions:
– Install an auto alert system to monitor the
routine patterns of withdrawals to help
determine fraudulent withdrawals
– Migrate towards chip cards and chip card
readers – less susceptible to skimming
Agenda
• Introduction
• General practices
• ATM Fraud Techniques
• PIN Security
• Accessing the Cash
• ATM Burglary attacks
• Conclusion
PIN Security
• Shoulder Surfing
• PIN Interception
PIN Security – Shoulder Surfing
• Direct observation
• Watching what number that person taps onto the
keyboard
• Use miniature video cameras – easily obtained
and can be discretely installed close to the PIN
Pad
PIN Security – Preventing Shoulder
Surfing
• Fix mirror on the fascia of the ATM – users will
see behind as they enter their info
• Ergonomic design of the ATM to prevent
shoulder surfing
• Consumer – allow body to cover the area of pin
entry
PIN Security – Preventing Shoulder
Surfing
• Educate users
• Place ATM in high-traffic area, with illuminated
signage panels and surrounding street lights
provide a secure and welcoming environment to
customers
PIN Security – Fake PIN Pad Overlay
• Transaction Reversal
Accessing the Cash – False ATM
presenter
• Fraud performed through addition of traps in
front of the dispense point
• Device covers or disguises the normal dispense
point
• ATM dispenses notes to false front and never
presented to consumer
• Consumer mistakenly assumes the ATM has
malfunctioned
• After customer leaves, criminal removes false
fronts and takes the currency
Accessing the Cash – False
ATM presenter
• Simplest method – use adhesive tape that
blocks the cash dispenser and holds delivered
banknotes
• Another method – use motorized devices that
transport the delivered notes into dedicated bins
Accessing the Cash – False
ATM presenter
False ATM presenter:
Accessing the Cash – Preventing
False ATM presenter
• Enhance presenter door mechanics with a more
robust locking mechanism
• Modify firmware and hardware
– After note stack reaches a certain position within the
presenter, the final delivery of the note stack is done
entirely by belts without assistance of the push plate
– With an external false cover, there will be much lower
force pushing notes against the tape resulting in most
or all notes to be retracted
Accessing the Cash –
Transaction Reversal
• Use a variety of methods to create an error
condition at the ATM resulting in a transaction
reversal due to reported inability to dispense
cash – though cash is legitimately accessible by
force
Accessing the Cash –
Transaction Reversal
E.g.
• ATM user request to withdraw $100
• User carefully remove only a portion of the notes
e.g. only $60
• $40 left in presenter
• Several seconds later, ATM times out and sends
an error message
• ATM retracts the remaining banknotes
• Dispenser is not able to count banknotes
• Transaction reversed
Accessing the Cash – Preventing
Transaction Reversal