Hackers break into UAE credit network to fund US purchases
Hugh Naylor
- Last Updated: September 04. 2008 11:34PM UAE / September 4. 2008 7:34PM GMT
Abu Dhabi // An international investigation is under way to find hackers believed to have stolen information from financial servers in the UAE to make fraudulent credit and debit card purchases in the US.
The scheme came to light after a number of employees at the US Embassy – and a handful of other US citizens – had unauthorised purchases show up on their credit and debit cards in recent months, prompting the embassy to issue a warning on its website.
“To date, all of the reported fraudulent charges have been made from the United States,” the message said. “We are aware of no fraudulent transactions originating in the UAE.”
MasterCard is co-operating with law enforcement officials and banks to investigate the issue, Chris Monteiro, the head of the company’s worldwide communications, wrote in an e-mail.
Visa, when contacted, did not respond to questions or comment on the case.
However the manager of an anti-fraud division at a credit union in North Carolina, in the US, speaking on the condition of anonymity, said Visa had warned that there had been “a network intrusion” in the UAE between February and August.
Visa told her that the intrusion had happened “at the processor level”, which she said suggested that computer hackers had penetrated the electronic records of organisations that acted as middlemen between merchants and credit card companies such as Visa and MasterCard.
These organisations, known as “processors” or “acquirers”, are sent credit and debit card information by local merchants. In turn, they process the information and send it on to credit card companies for billing.
“Visa is having a hard time figuring this problem out,” the credit union employee said.
The case has also prompted concerns that security measures designed to protect personal financial information may be too lax in the UAE.
Numerous establishments in Abu Dhabi print customers’ full details, such as customer names, entire card numbers and expiration dates, on receipts.
Many countries, including the US, have laws requiring such details be truncated to prevent sensitive information from being stolen.
Galen Clarke, 22, a photographer for The National who moved from the US in July, noticed his entire credit card number was printed out on several receipts. He took a closer look at them after learning an unauthorised US$642 (Dh2,358) had been charged to his Visa debit card account on Aug 23. As a new resident, Mr Clarke had not yet opened a bank account in the UAE.
Although he was in the UAE at the time, the purchases included $90 of petrol in Florida. Other transactions originating in the US happened at about the same time that he was dining at the Beach Rotana Hotel & Tower in Abu Dhabi.
“I tried using my cheque card to pay for my meal at the Brauhaus, and it came back declined, which I thought was weird because I knew I had the money,” said Mr Clarke, who was later reimbursed by Visa for the fraudulent charges made on his card. “My account went down to $180 – there was no way to explain that.”
Doug Johnson, the vice president of risk management at the American Bankers Association (ABA), a professional association that promotes the US banking industry, said incidents of credit and debit card fraud in the UAE were on the rise, as they were in much of the rest of the world.
It was possible that global hacking networks could have tampered with certain companies’ financial information, he said. Hacker networks have grown “extraordinarily sophisticated”, modelling themselves on multinational corporations operating in countries all over the world, he said.
“The hackers sell data to anyone who cares to buy,” said Mr Johnson. “They might advertise it on the internet, and then resell it further down the chain. Hackers could be from Eastern Europe, for example, and sell their stolen data to people who make clone cards in Latin America.”
Mr Johnson said printing customer names and full card numbers on receipts contravened the policies of most credit card companies.
Recent years have seen an increasing number of credit card and get-rich-quick schemes in the UAE, which have wrested millions of dirhams from residents.
A Middle East manager for an anti-fraud division of a large international bank, who spoke on condition of anonymity, said there had been a rise in so-called “skimming” incidents at ATM machines. Under a typical skimming scheme, criminals rig ATM machines with card-reading data and cameras to steal pin codes. They then compile the information to make clone debit cards.
“There was a rash of this occurring during Christmas time this year,” said the banking official, who is based in the UAE.
hnaylor@thenational.ae
See also
Other UAE stories
Your View
- Will you send your children to driving school?
- How will the new rent laws affect you?
- Have you had difficulties obtaining drugs at a pharmacy?
- Have you had problems getting your children enrolled in schools?
- Why do you think the Bu Tinah Islands deserve to be named one of the new natural wonders of the world?
Most popular stories
- 800 firms banned from hiring workers
- Prison and Dh115m fine for former chief executive of Dubai Islamic Bank
- Angry words fly as Emirates eyes Canada
- Target practice for Pacquiao
- Appeals court hears the case of the kissing couple
- Cut the power and save money
- Traffic ‘Disneyland’ to teach children
- ADIA shows solid return in first time fund review
- Pacquiao gives Filipino expats pride in country
- McDonald’s supersizes sales in UAE


Added: 09/16/08 04:45:00 AM
Well i have read the topic and i wish to say some stuff about how this credit cards hackers get the ways to use it, it is easy to say that I tried the way but i didn't use it on anybody I only used it to see how it works, and I found out how it works.
I can say that the most important part is that when companies in UAE don't go by the book, or by the rules of their companies to get more money by selling stuff to there employees...
When I order a phone for example the company would ask for the credit card number, name, 3 digts, etc...
and the most important thing that they don't ask for, is the credit card copy to make sure the owner is the one doing the transaction, and by the law this is a rule that most companies ignore to make it easy for hackers to buy stuff. So we can say hackers are somehow involved in this thread but companies are the main part and they must get some new stricter rules.
Well, some would say I'm not sure of what I am talking about, but as I said I know how they get the credit card info, and I know how they use it, its easy to catch the hackers, but its hard to put any evidence on them.
There are two kind of hackers, hackers that sell the credit cards that they have stolen from websites such as www.buy.com, then they sell it to people at a low price, and those people use it to scam, or steal others.
and the other kind is hackers that steal credit cards from websites, and use it to scam or steal other peoples money.
In the UAE we are talking about a hacker that steals credit cards and uses them to buy his own stuff + stuff to sell...
It's easy to find him, cause if he bought something he will need to sell it to someone and that someone is easy to find.
I am 100% sure of who did this hacking stuff in UAE, and the government already got him after some companies complained, and when that happened Dubai police officers caught him and the way was by tracking a E-card for a concert ticket.
The government did not catch him for all what he did, they only caught him cause some companies put a finger on that guy, not one evidence they got on him, only that the guy that bought the ticket said that I bought it from that guy, and this is not enough to put someone in jail.
Hackers have been in the UAE for a long time, and people tried before to tell the government but the government never did anything to them.
I would like people to know that this guy did not only sell once or twice, this guy got from 2 years hacking over 2mill Dhs, and this is a big number for US to think of.
This hacker has stolen more than one kind of stuff:
1) airline tickets
2) concert tickets
3) cds + accessories
Thanks for taking your time to read this. Sorry for not putting my real name but i don't want to get deeper than this.
Peace,
Anti-hacker
Anti hacker