Clarkhoward Home

Mon-Fri 1-4pm ET
Stations near you | help

Video Minute Archives
Daily Audio Archives
Rip-off Alerts
Call of the Week

Today's Show Notes
Previous Show Notes
Clark's Greatest Hits
Free and Cheap

Ask Team Clark
Call 10am-7pm ET
(404) 892-8227

Member Center
Blogs
Newsletters
Message boards
Meet the Team

Appearances
Books
Photos
TV
Talk to Clark 1-4pm ET:
(877) 87-CLARK or
(404) 872-0750

Advertisement
Ask Clark  Looking for something on the site? Search for it here!  Also see Clark's Greatest Hits
help

Jul 02, 2008 -- Citibank ATMs compromised, PINs stolen

There's been a widespread security breach at some 5,700 Citibank ATMs. Heed this special warning if you've used a Citibank ATM (including those found at 7-Eleven stores) at any point this year.

Criminals hacked into the bank's system and were remotely able to capture account numbers and PINs. They then made duplicate cards that were used to withdraw money from accounts for about 7 months.

The banking industry's longtime rule has been that the burden of proof was on you if your PIN was stolen. They believed their system was impenetrable and if something went wrong, well, you must have been at fault by not protecting your account or PIN. But the hacker community shares info about how to break into back-end systems on a variety of message boards.

The real problem is that our banks rely on 1960s ATM card technology. Over in Europe, they've long since switched to using smart chips in ATM cards. These smart chips defeat the ability of hackers to duplicate a card should they capture a number.

Washington D.C. has also been complicit in this backwards-looking policy. Federal regulators who are in cahoots with the banks have not followed through on requiring them to follow international banking security standards.

The takeaway for you is that you've got to thoroughly monitor your account and follow up on any discrepancies.

Meanwhile, the folks at Wired magazine originally broke the Citibank story. And Citibank, to its shame, is still being hush-hush about the number of people affected and the amount of money that's been stolen. Ukrainian immigrant Yuriy Rakushchynets and 2 others are the likely culprits of the crime.

Our banking industry operates at below-Third World standards when it comes to data safety. It's well past time for our government to mandate that the banks adhere to recognized world standards in the field. Clark also thinks banks should be required to provide full disclosure to the media and the American people when breaches like this one occur.


Unfortunately, Clark won't be able to answer any questions submitted via commenting. If you have a question, please try posting it to our message boards.

Add your comment

Security Image * Please enter the code shown at left
what's this?

What others are saying

  • not just atm
    Citibank just froze my online access along with virtual numbers I use to pay bills. They will be sending a new card and I'll have to start all over again. This happened about 2 years ago also. What a pain!
  • They didn't "hack the mainframe"
    Clark, in your commentary on this you said "Criminals hacked into the bank's mainframe...". Where did you get this information from? It's not in the Wired article, and based upon other reports I read this is inaccurate. Can you please correct this article?
  • credit card fraud - its the LAW you must tell
    Citi Bank cannot be hush-hush with the new credit card laws. IF there is a breach or suspected breach of name and / or any identifying character that can be used for stealing credit card information for fraud, that company MUST inform each and every cardholder that this suspected breach has occurred for. Full Stop. No turning back, they must or they will be heavily fined to the point of having to close shop, not to mention they will lose the ability to use credit cards at all! California’s laws started it all – but now you must tell.
  • LAWS are LAWs
    Citi Bank cannot be hush-hush with the new credit card laws. IF there is a breach or suspected breach of name and / or any identifying character that can be used for stealing credit card information for fraud, that company MUST inform each and every cardholder that this suspected breach has occurred for. Full Stop. No turning back, they must or they will be heavily fined to the point of having to close shop, not to mention they will lose the ability to use credit cards at all! California’s laws started it all – but now you must tell.
  • Credit Cards
    Banks have had higher profit margins than gas companies and they can't keep all the sensitive information they want from us safe shocking! And we need less regulation? Banks should be hit with the windfall tax with some banks over the past few year reaching 20% profit margins. At least I am smart enough not to use a bank, they charge you to breathe the air in those places. America is all about greed, not right and wrong anymore. Uncontrol capitolism will destroy us, capitolism is the greatest thing we have but left unsupervised it eats itself to death.
  • European measures
    In addition to issuing credit cards with pins known only to the owner, european have implemented another measure which is a low-tech as it can be: they simply do not accept credit cards almost anywhere. We had huge troubles all over western europe couple of summers ago including giant hypermarkets in Austria, Germany, and Italy. Cannot beat that security!

Advertisement


This week's poll
Do you like the idea of auto insurers switching to a pay-as-you-drive model -- where how, when and where you drive may be monitored?
Yes, I'm all for any approach that can save me money.
No, it's too much like having Big Brother in the back seat.
I'm not sure. I'd like the savings, but I don't know if I'd feel comfortable being monitored.
see previous polls


Advertisement