USENIX Security2021Top-tier venue
Swiped: Analyzing Ground-truth Data of a Marketplace for Stolen Debit and Credit Cards
Maxwell Aliapoulios, Cameron Ballard, Rasika Bhalerao, Tobias Lauinger, Damon McCoy
Abstract
This paper presents the first empirical study of ground-truth data from a major underground shop selling stolen credit and debit cards. To date, there is little quantitative knowledge about how this segment of the underground economy operates, despite it causing fraud losses estimated at billions of dollars a year. Our analysis of four years of leaked transactional data allows us to characterize this shop's business model, sellers, customers, and finances. The shop earned close to 24 M before labor and infrastructure costs, with profits growing consistently over the years. Revenue from stolen magnetic stripe data was flat in 2017 and 2018, but it still accounted for 92.2% of gross revenue in 2018. The top 5 magnetic stripe buyers in 2018 spent over $100 k each on stolen magnetic stripe accounts, indicating that they were likely able to evade EMV and transactional risk-based anti-fraud measures. Around 3% of the shop's inventory was card-not-present data used for online fraud. Supply and demand were increasing, but these accounts only made up 7.8% of gross revenue in the last year of the leaked data. The shop paid sellers higher commission rates for stolen card-not-present accounts, yet it appeared unable to attract supply at the same level as magnetic stripe accounts. Based on the perspective of this one shop, it appeared to be more difficult in the U.S. to steal large amounts of card-not-present accounts as opposed to magnetic stripe accounts. This paper makes the following contributions: • We characterize the behavior of buyers, and show on the basis of pricing and demand that buyers had clear preferences among card issuers and card types. • We study the state of U.S. EMV deployment through the lens of this shop. While effects of EMV were visible, deployment had no major impact on the shop's prosperity.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f2210d35-9997-4e57-bc14-37ddf841c3d8Cited by top-tier papers3
- SoK: Digging into the Digital Underworld of Stolen Data MarketsTina Marjanov, Alice HutchingsS&P 2025
- Mixed Signals: Analyzing Ground-Truth Data on the Users and Economics of a Bitcoin Mixing ServiceFieke Miedema, Kelvin Lubbertsen, Verena Schrama, Rolf van WegbergUSENIX Security 2023
- Know Your Cybercriminal: Evaluating Attacker Preferences by Measuring Profile Sales on an Active, Leading Criminal Market for User Impersonation at ScaleMichele Campobasso, Luca AllodiUSENIX Security 2023
Builds on6
- Plug and Prey? Measuring the Commoditization of Cybercrime via Online Anonymous MarketsRolf van Wegberg, Samaneh Tajalizadehkhoob, Kyle Soska, Ugur Akyazi et al.USENIX Security 2018 · 97 citations
- Platforms in Everything: Analyzing Ground-Truth Data on the Anatomy and Economics of Bullet-Proof HostingArman Noroozian, Jan Koenders, Eelco van Veldhuizen, Carlos Hernandez Gañán et al.USENIX Security 2019 · 40 citations
- Fear the Reaper: Characterization and Fast Detection of Card SkimmersNolen Scaife, Christian Peeters, Patrick TraynorUSENIX Security 2018 · 34 citations
- Please Pay Inside: Evaluating Bluetooth-based Detection of Gas Pump SkimmersNishant Bhaskar, Maxwell Bland, Kirill Levchenko, Aaron SchulmanUSENIX Security 2019 · 12 citations
- The Cards Aren't Alright: Detecting Counterfeit Gift Cards Using Encoding JitterNolen Scaife, Christian Peeters, Camilo Velez, Hanqing Zhao et al.S&P 2018 · 11 citations
Related papers
- Kiss from a Rogue: Evaluating Detectability of Pay-at-the-Pump Card SkimmersNolen Scaife, Jasmine D. Bowers, Christian Peeters, Grant Hernandez et al.S&P 2019 · 10 citations
- Inducing Authentication Failures to Bypass Credit Card PINsDavid A. Basin, Patrick Schaller, Jorge Toro-PozoUSENIX Security 2023
- Data Breaches, Phishing, or Malware?: Understanding the Risks of Stolen CredentialsKurt Thomas, Frank Li, Ali Zand, Jacob Barrett et al.CCS 2017 · 248 citations
- Boxer: Preventing fraud by scanning credit cardsZain ul Abi Din, Hari Venugopalan, Jaime Park, Andy Li et al.USENIX Security 2020
- Economic Factors of Vulnerability Trade and ExploitationLuca AllodiCCS 2017 · 82 citations
