Phone bug discovered in Aussie bank branch

 

Cleaner installed wiretap to steal card numbers and PIN numbers.

A major Australian bank has discovered a telephone bug [pictured below] installed inside a branch, being used to siphon the credit and debit card information of unwitting consumers.

The meticulously handcrafted device, smaller than the palm of a hand, was pinned carefully to telephone cable that ran along the carpet floor of the bank's metropolitan branch office.


Two inconspicuous cuts were made in the wire to attach the bug. It would listen for keypad tones as unsuspecting customers keyed in their PIN numbers at the automatic teller.

Each tone woke the device from slumber, which it diligently broadcast over a handpicked radio frequency.

The attacker waited in the bank’s carpark and recorded the tones on a laptop. Each tone was then matched to a number, revealing the customer’s PIN.

Corresponding card information was also being copied and stored. The brazen attacker had swapped the terminal on the teller's desk with a skimming device that was capturing enough bank data for replica cards to be manufactured.

The thief needed only match the time signatures at which the card and PIN number were swiped to have unfettered access to potentially hundreds of accounts.

Navid Sobbi, the phone interception expert who busted the scam, held a professional respect for the effort put into the bug.

“It was a work of art,” Sobbi said. “It is one of the best made and tidy bugs I have come across.”

The device was fully sealed save for an exposed screw head which was used to tune the radio frequency over which the PIN numbers were broadcast.

A cleaner was found to have installed both the bug and the skimming device.

“It’s almost always the cleaners,” Sobbi said, speaking of the dozens of interception cases he has foiled this year. “They have the access and are the most vulnerable – they often stand to make a lot of cash and that’s tempting considering they might not be paid a lot.”

However, the bug wasn’t the most sophisticated Sobbi had encountered.

He had recently stumbled on a government military-grade interception device installed in the bedroom of a residential property. The device transmitted captured audio via microwave links and was instantly recognisable as a government plant.

It was deactivated, but Sobbi’s bug hunting kit was able to identify particular metallic components inside the device.

In another case, Sobbi took a call from a client concerned that an office had been wiretapped.

During the drive to the property, Sobbi was called by police to cease and desist: the client had phoned Sobbi to request the search within proximity of the bug. That tipped off police who soon after raided the premises.

“If you ever suspect a phone bug,” Sobbi said “don’t talk about it if you are within range.”

Though 20 percent of Sobbi's work involved searching for suspected bugs, this year he had also found several hidden cameras and keyloggers implanted on the backs of computers.

Lasers had in some cases been used to listen in on corporate meetings, a ploy ultimately foiled by a mock meeting Sobbi established to detect the location of the laser.

“With enough tweaking, even a whisper can be heard,” Sobbi said of the laser.

Most of Sobbi’s cases involved suspected espionage. His team of six within National Surveillance and Intelligence serviced big business like Australia’s mining giants, government agencies and law firms. The company regularly performed “bug sweeps” of conference rooms ahead of sensitive meetings.

Sobbi also ran forensic scans of mobile devices with the same equipment used by police.

This service was a favourite of lawyers, big business and individual clients who suspected foul play by staff and partners.

“When staff leave, companies often want to know if incriminating text messages or phone calls were sent," he said. "Husbands and wives also want to check out if their phone was tampered or tracking software had been installed.”

Copyright © SC Magazine, Australia


Phone bug discovered in Aussie bank branch
 
 
 
 
Top Stories
Photos: Highlights from SAP Sapphire Now 2013
All the keynote action from one of the world's biggest SAP events.
 
How do I: Improve my presentation skills
A repeatable process to follow.
 
Photos: NextDC builds S1 data centre
Prepares for September launch.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...

Latest VideosSee all videos »

Bankwest builds continuous delivery capability
Bankwest builds continuous delivery capability
To automatically deploy test/dev sandboxes by mid-year.
Veterans' Affairs sets sights on modernisation
Veterans' Affairs sets sights on modernisation
Data safe with Human Services, CIO says.
Citi Australia drops platform customisations
Citi Australia drops platform customisations
Technology chief shifts focus from building to leveraging systems.
VicRoads restructures IT team
VicRoads restructures IT team
Department moves to align with industry benchmarks.
Zurich Australia extends IT team offshore
Zurich Australia extends IT team offshore
Malaysian staff served from Australian data centres.
Leigh Berrell - Utilities CIO of the Year
Leigh Berrell - Utilities CIO of the Year
Yarra Valley Water CIO Leigh Berrell accepts his Benchmark Award for Utilities CIO of the Year.
Wayne McMahon - Retail CIO of the Year
Wayne McMahon - Retail CIO of the Year
Domino's Pizza CIO Wayne McMahon accepts his Benchmark Award for Retail CIO of the Year.
Inside Perpetual's ongoing IT transformation
Inside Perpetual's ongoing IT transformation
CIO Jenny Levy discusses how outsourcing will help the firm "simplify, refocus and grow".
Managing Complexity - Defence's Daniel McCabe
Managing Complexity - Defence's Daniel McCabe
Daniel McCabe, Assistant Secretary of Australia's Department of Defence, provides the audience at the iTnews Data Centre Strategy Summit with a deep dive into the organisation's data centre consolidation program.
How Facebook designed the data centre from scratch - Marco Magarelli
How Facebook designed the data centre from scratch - Marco Magarelli
The full keynote by Facebook data centre architect Marco Magarelli at the Australian Data Centre Strategy Summit. Magarelli details the design considerations behind the social network's Prineville, Oregon; North Carolina and Luleå, Sweden data centres.
Modernising Legacy Data Centres - Telstra's Jon Curry
Modernising Legacy Data Centres - Telstra's Jon Curry
Telstra general manager of managed data centres Jon Curry guides the audience at the iTnews Australian Data Centre Summit through the build of the telco's Clayton, Victoria data centre.
NSW Government launches NABERS data centre rating tools
NSW Government launches NABERS data centre rating tools
Matthew Clark from the NSW Department of Environment guides facilties managers through the details of the new NABERS data centre energy rating tool at the Australian Data Centre Strategy Summit.
NABERS launch panel: Australian Data Centre Strategy Summit
NABERS launch panel: Australian Data Centre Strategy Summit
Matthew Clark (NSW Dept of Environment), Greg Boorer (Canberra Data Centres), Glenn Allan (National Australia Bank), Mike Andrea (Strategic Directions) and Bob Sharon (Green Global Consulting) discuss the impact of the NABERS data centre rating.
Judges notes: Fortescue Metals [The Benchmark Awards]
Judges notes: Fortescue Metals [The Benchmark Awards]
iTnews' panel of judges discuss Fortescue Metals 'New World of Work" project, one of three shortlisted finalists for the Industrials category of the CIO Benchmark Awards.
Judges notes: Retail [The Benchmark Awards]
Judges notes: Retail [The Benchmark Awards]
iTnews' panel of judges discuss the shortlisted finalists for the Retail category of the CIO Benchmark Awards.
Judges notes: Pacific Aluminium [The Benchmark Awards]
Judges notes: Pacific Aluminium [The Benchmark Awards]
iTnews' panel of judges discuss Pacific Aluminium's lightning fast service desk refresh, one of three shortlisted finalists for the Industrials category of the CIO Benchmark Awards.
Judges notes: Domino's Pizza [The Benchmark Awards]
Judges notes: Domino's Pizza [The Benchmark Awards]
iTnews' panel of judges discuss Domino's Pizza's shift to hosted services, one of three shortlisted finalists for the Retail category of the CIO Benchmark Awards.
Judges notes: McDonald's Australia [The Benchmark Awards]
Judges notes: McDonald's Australia [The Benchmark Awards]
iTnews' panel of judges discuss McDonald's Australia's new self-service portal for employees, one of three shortlisted finalists for the Retail category of the CIO Benchmark Awards.
Judges notes: ING Direct [The Benchmark Awards]
Judges notes: ING Direct [The Benchmark Awards]
iTnews' panel of judges discuss ING Direct's 'Bank in a Box', one of three shortlisted finalists for the banking and finance category of the CIO Benchmark Awards.
Judges notes: Yarra Valley Water [The Benchmark Awards]
Judges notes: Yarra Valley Water [The Benchmark Awards]
iTnews' panel of judges discuss Yarra Valley Water's insourcing project, one of three shortlisted finalists for the Utilities category of the CIO Benchmark Awards.
Latest Comments
Polls
Do you prefer the Coalition's NBN policy?

   |   View results
Yes
  19%
 
No
  81%
TOTAL VOTES: 1615

Vote