Credit-card fraud's business model
A credit card is swiped through machine at a Chicago toy store.
TEXT OF STORY
Tess Vigeland: So riddle me this. What does a criminal mastermind, assuming you call them that, do with 130 million credit-card numbers? How exactly do fraudsters make money? Marketplace's Rico Gagliano looked into the business model.
RICO GAGLIANO: Well that's easy, right? Pick a number, log on to Amazon and start buying stuff. Jonathan Penn is vice president at Forrester Research. He says it's a bit more complicated. In fact...
JONATHAN PENN: Complicated, I don't think, does justice to the level of maturity of the economy around stolen data.
He describes a network of players at different levels. "Harvesters" -- like, allegedly, Albert Gonzalez -- fall somewhere in the middle of the network. They make their money by stealing all those millions of data records and selling them to wholesalers. And the wholesalers then sell the records online, one at a time, to other criminals.
PENN: And it goes, you know, it can go for a few cents for a record, it may be 10 times that. You know, credit-card numbers on their own are worth less than credit-card numbers in conjunction with other personal information -- like your name, your social security number, or even things like your pet's name.
Wired.com Senior Editor Kevin Poulsen knows all about what happens next. A former hacker, he created Wired's security blog Threat Level. He says criminals take the stolen records they've purchased, and program them onto the magnetic stripe of, say, old gift cards.
KEVIN POULSEN: They'll use anything, they'll use phone cards, anything that has a magnetic stripe on it. And if it's a case where PIN numbers were stolen, then they can go to an ATM, put the card in the ATM, put in the PIN and pull out cash from people's accounts.
Poulsen says most recent examples of that scam, and similar ones, allegedly involved Gonzalez.
POULSEN: With this latest indictment, Gonzalez now ties up every major credit or debit-card breach we know about over the past 5 years. It all comes back to him.
If so, this still isn't the end of data theft. Jonathan Penn of Forrester research says it's estimated to be a multi-billion dollar market, possibly even bigger than the illegal drug trade.
In Los Angeles, I'm Rico Gagliano for Marketplace.