ad info




CNN.com
 MAIN PAGE
 WORLD
 U.S.
 LOCAL
 POLITICS
 WEATHER
 BUSINESS
 SPORTS
* TECHNOLOGY
   computing
   personal technology
 SPACE
 HEALTH
 ENTERTAINMENT
 BOOKS
 TRAVEL
 FOOD
 ARTS & STYLE
 NATURE
 IN-DEPTH
 ANALYSIS
 myCNN

 Headline News brief
 news quiz
 daily almanac

  MULTIMEDIA:
 video
 video archive
 audio
 multimedia showcase
 more services

  E-MAIL:
Subscribe to one of our news e-mail lists.
Enter your address:
Or:
Get a free e-mail account

 DISCUSSION:
 message boards
 chat
 feedback

  CNN WEB SITES:
CNN Websites
 AsiaNow
 En Español
 Em Português
 Svenska
 Norge
 Danmark
 Italian

 FASTER ACCESS:
 europe
 japan

 TIME INC. SITES:
 CNN NETWORKS:
Networks image
 more networks
 transcripts

 SITE INFO:
 help
 contents
 search
 ad info
 jobs

 WEB SERVICES:

Computing

Hackers - Insurgency on the Internet
Main Page | Bracing for Cyberwar | Hacking Primer | Scenes from the 'Hacker Underground' | Hacking: Two Viewpoints | Timeline | Gallery | News Archive | Discussion | Related Sites

Rebuffed Internet extortionist posts stolen credit card data

Image

January 10, 2000
Web posted at: 4:50 p.m. EST (2150 GMT)

From staff and wire reports

NEW YORK (CNN) -- An anonymous computer hacker stole credit card numbers from an Internet music retailer and posted them on a Web site after an attempt to extort money from the company failed.

The retailer, CD Universe, brought in Internet security specialists Monday to shore up its Web site, as the FBI tried to track down the hacker and customers contacted credit card companies to see if their cards were compromised.

The unknown hacker claimed to have stolen 300,000 credit card numbers from CD Universe and distributed up to 25,000 of them on a Web site after the retailer refused to pay a $100,000 ransom, according to The New York Times.

The computer intruder claimed in e-mails to the Times that he used some of the credit card numbers to obtain money for himself.

The hacker, thought to be based in Russia, used a Web site to distribute the stolen numbers for two weeks to thousands of other people, said Elias Levy of SecurityFocus.com, a computer security firm. The hacker's site was shut down Sunday morning.

The parent company of CD Universe, eUniverse of Wallingford, had not yet determined how the Web site was compromised or how many customers may have been affected.

"There's no way to tell. It's not a good situation," said Brett Brewer, a vice president of eUniverse.

Brewer said that as an emergency measure, eUniverse was able to cancel customers' credit card numbers that had been stolen and was notifying those cardholders by e-mail. He said the credit card companies would automatically give those customers new cards.

CD Universe and eUniverse were working with the FBI to track the hacker. But a lack of international laws that deal with Internet crime could hinder their efforts.

"The Internet creates a whole new class of criminal," Levy told the Times. "On the Internet you can have criminals coming from countries where we have no extradition treaties. How do you prosecute these people, or even investigate their crimes?"

Hackers
 
  • Bracing for Cyberwar
  • Hacking Primer
  • Hacking: Two Views
  • Timeline
  • Gallery
  • Discussion
  • TIME: Counterhacking 101
  • Related Sites

  •  

    The hacker, identifying himself as Maxim, a 19-year-old Russian, in an e-mail to the Times, said he exploited a security flaw in the software used to protect financial information at CD Universe's Web site. He said he sent a fax to the company last month offering to destroy his credit card files in exchange for the ransom.

    When he was rebuffed, he said, he began posting the numbers on a Web site called Maxus Credit Card Pipeline on December 25. The hacker e-mailed the Times the numbers for 198 credit cards as proof of the theft.

    With a single mouse click, a visitor could obtain a credit card number, name and address that the site claimed was obtained "directly from the biggest online shop database."

    The numbers were real, said the Times, which contacted the credit card owners. At least one owner confirmed she had been a CD Universe customer.

    Maxus wrote in an e-mail that he has participated in illegal credit card activities since 1997. He indicated in an earlier message that he had attempted to start a legal Internet business involving credit card processing, but discovered he could subvert infiltrate credit card verification software often used by e-commerce companies.

    "Pay me $100,000 and I'll fix your bugs and forget about your shop forever," the electronic extortionist reportedly warned CD Universe in a fax. "Or I'll sell your cards and tell about this incedent (sic) in the news."

    The credit card pipeline included a guest book for visitors, many of whom complained that posted credit card numbers had been declined. They urged Maxum to provide fresh ones.

    "If you visit the guest book you will find a number of criminal types talking about buying and selling the credit cards. This is very disturbing. It realizes the fear people have about online commerce," Levy said.

    Since credit card users are generally liable for no more than $50 for fraudulent use of their cards, "the real danger here is for the credit card companies and merchants that must deal with this fraud," he added.

    Like many online retailers, CD Universe rode a burgeoning interest in online shopping at Christmas to bust open sales projections for music, movies, videos and games. CD Universe's sales were $9.1 million last year and are projected to rise to $16 million this year, Brewer said.

    The Associated Press contributed to this report.


    RELATED STORIES:
    Pentagon prepares for war by keystroke
    January 5, 2000
    Reporter's notebook: Hackers are all business at annual congress
    January 4, 2000
    Governments ready to fight cyber-crime in new millennium
    January 2, 2000
    Anti-virus vendors on alert for new year
    December 30, 1999
    Feds leave doors open for hackers
    December 22, 1999

    RELATED SITES:
    CD Universe
    SecurityFocus.com
    Note: Pages will open in a new browser window
    External sites are not endorsed by CNN Interactive.

     LATEST HEADLINES:
    SEARCH CNN.com
    Enter keyword(s)   go    help

    Back to the top   © 2001 Cable News Network. All Rights Reserved.
    Terms under which this service is provided to you.
    Read our privacy guidelines.