30 million payment cards listed on fraud marketplace


Hackers have put the payment card details of more than 30m Americans and over one million foreigners up for sale on the Internet’s largest carding fraud forum, Joker’s Stash.
The latest “card dump” was listed under the name BIGBADABOOM-III on Joker’s Stash but security experts at Gemini Advisory have traced the stolen card data back to the US East Coast convenience store chain Wawa.
Back in December, Wawa disclosed a major security breach in which the company admitted that hackers had planted malware on its point-of-sale (POS) systems. According to the company, the malware collected the card details for all of its customers who used either credit or debit cards to buy goods or gasoline at all of its 860 convenience store locations.
To make matters worse, the malware operated for months between March and December of last year before it was finally removed from Wawa’s systems.
Card details for sale
As a result of the prolonged infection period and the compromise of hundreds of different locations, the attackers behind the breach were able to collect quite a large cache of payment card details. In a blog post on its site, Gemini Advisory provided additional context on the scope of the Wawa data breach, saying:
“Since the breach may have affected over 850 stores and potentially exposed 30 million sets of payment records, it ranks among the largest payment card breaches of 2019, and of all time. It is comparable to Home Depot’s 2014 breach exposing 50 million customers’ data or to Target’s 2013 breach exposing 40 million sets of payment card data. Joker’s Stash has uploaded records from several major breaches in the past.”
Following the release of Gemini Advisory’s report, Wawa released its own press release in which it said that the company is aware that customer card data is now being offered for sale online. The convenience store chain did not contest the accuracy of the report which effectively confirms that the latest Joker’s Stash card dump originated from its systems.
According to Gemini Advisory, the details of US-issued cards from the Wawa data breach are being sold on the site for just $17 per card while those of international cards are priced much higher at $210 per card.
Via ZDNet
Hackers have put the payment card details of more than 30m Americans and over one million foreigners up for sale on the Internet’s largest carding fraud forum, Joker’s Stash. The latest “card dump” was listed under the name BIGBADABOOM-III on Joker’s Stash but security experts at Gemini Advisory have traced…
Recent Posts
- Quordle hints and answers for Wednesday, February 19 (game #1122)
- Facebook is about to mass delete a lot of old live streams
- An obscure French startup just launched the cheapest true 5K monitor in the world right now and I can’t wait to test it
- Google Meet’s AI transcripts will automatically create action items for you
- No, it’s not an April fool, Intel debuts open source AI offering that gauges a text’s politeness level
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010