Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 56 guests and 1 member online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow CEH - Certified Ethical Hackerarrow Fraudulent activity on my checking Acct
EH-Net
May 26, 2012, 01:54:57 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Fraudulent activity on my checking Acct  (Read 3920 times)
0 Members and 2 Guests are viewing this topic.
Joshsevo
Sr. Member
****
Offline Offline

Posts: 263


View Profile
« on: November 16, 2010, 01:52:00 PM »

So I have been a member on here for a few months now.  Soon to be graduate with a Computer Forensics & Network Security degree....

Anyways.... my checking acct debit card was used for a few purchases overseas last week.  Places like Germany, The UK etc...  The things that were purchased were a train ticket to Berlin and someone tried paying their water utility bill in the UK as welll as smaller withdrawls to check to see if the acct was active I assume.

I know the train ticket one is a waste of time, meaning it's pointless trying to track this down cause it would be untrackable.

But the Water bill interested me.  The amount charged was $320.99 ( very large water bill)  The company was Angelian Water Services, (see links)
http://www.anglianwater.co.uk/
http://en.wikipedia.org/wiki/Anglian_Water


Now one could assume that with any utility payment there has to be an associated account number.  So I am wondering if I should pursue this and see what information I can gather about the person that used my card#.  What are the likely hood that the Water company gives me their info?  Unlikely I'm sure.

Even though my bank gave me the money back that was charged and has since cancelled the card I would like to know what you guys think I should do, if anything at all.  Maybe our UK friends on the site would lend a hand to a brother.
Logged

CHFI, C|EH, Security+, CPT
Grendel
Full Member
***
Offline Offline

Posts: 168


View Profile WWW
« Reply #1 on: November 16, 2010, 01:56:24 PM »

I would admit I would have the same curiosity and want to know the who/why, but it would eventually be tempered with the question "to what end?" Even if you were able to get the utility company to illegally give you PII, then what? Have a chat?

I read about this one girl in NY who came across someone who stole her account info and chased her down throughout the subways, bus system and all the time called the cops who eventually caught her. Fun (risky) stuff, but not sure I have the energy to do a follow-through.
Logged

- Thomas Wilhelm

http://HackingDojo.com
SephStorm
Sr. Member
****
Offline Offline

Posts: 416


View Profile WWW
« Reply #2 on: November 16, 2010, 08:29:49 PM »

I would get as much info as possible, and pass it on to Law Enforcement. Make sure any credit accounts are good as well, any evidence you obtain (legally) can assist in making repairs.
Logged

Data_Raid
Full Member
***
Offline Offline

Posts: 149


View Profile
« Reply #3 on: November 17, 2010, 02:35:07 PM »

I don't think that it's worth your time and energy pursuing this, especially since the card has been cancelled and you have received a refund. Hopefully your bank has tracked down the criminals.
I also doubt that Anglian Water will tell you the name or account number of the criminal that used your card to pay for the bill. They would most probably require an account number or an address to reference the bill but using just your card details I doubt it.

It sounds like your card may have been cloned, did you use your card in an ATM recently or shop online or use it anywhere else that could be suspicious?
Logged

All men by nature desire knowledge.

Aristotle
Joshsevo
Sr. Member
****
Offline Offline

Posts: 263


View Profile
« Reply #4 on: November 18, 2010, 01:28:55 PM »

Nope nothing.  Don't go out to eat anywhere, have no money in general.  Kinda broke.  I have not bought anything overseas or paid for any porn susbcriptions that they could have gotten it off of. 

I think that a shady individual at some place that I used my card for copied it down.  I doubt it's cloned.  Just stole my info off a bill I paid and sold it to an online forum.

Sucks but I am interested in where this can go.  If nothing comes of it then oh well.  Angelian water service sent a reply saying they will take 10 days to get back to my response.

10 days? Nice customer service!

Logged

CHFI, C|EH, Security+, CPT
Joshsevo
Sr. Member
****
Offline Offline

Posts: 263


View Profile
« Reply #5 on: November 30, 2010, 10:53:15 PM »

So here is the repsonse from the UK water company

Dear Mr. Xxxxxx

 

Thank you for your email.

 

Unfortunately we cannot locate the property with the details mentioned in the letter.  To ensure that our records are updated, could you please provide us with the complete details of the property and the serial number of the meter serving the property.

 

If we can be of further assistance, please email or telephone on 08457 91 91 55 where our customer services staff will be pleased to help.

 

Yours sincerely

Customer Services
Logged

CHFI, C|EH, Security+, CPT
Joshsevo
Sr. Member
****
Offline Offline

Posts: 263


View Profile
« Reply #6 on: November 30, 2010, 10:54:50 PM »

Then I go this a few days later also.  Seems whoever wrote the first one said the wrong stuff.


Dear Mr Xxxxxxxx

 

Thank you for your email of 16th November and please accept my sincere apologies that our response dated the 22nd November in no way addressed your query or concerns.

 

I regret that from the information that is contained within your email we would not be able to trace the payment within our billing systems.  I regret that I must also advise that even if we were to trace the payment we would be unable to confirm who used the card with any degree of certainty as this may not be the account holder named on the account to which the credit/money was allocated.  With this in mind, and due to UK Data Protection Laws, I regret that we would be unable to provide any information that would be of help to you in this matter.

 

As you have confirmed that this matter has already been reported to your bank, who in turn have stopped the payment, I trust that the money has now been credited back to your bank account.  I also trust that the bank have reported the matter to the relevant authorities who will be able to trace the fraudulent transactions that have been made and hopefully identify who used your card.  I also trust that the bank issued you with a new card to avoid any further fraudulent transactions from being carried out against your bank account.

 

I apologise that we are unable to assist you in this matter and that our first response was in no way adequate to address and answer your email.

 

Yours sincerely

 

 

Customer Services

 
Logged

CHFI, C|EH, Security+, CPT
Joshsevo
Sr. Member
****
Offline Offline

Posts: 263


View Profile
« Reply #7 on: November 30, 2010, 11:17:27 PM »

I just replied to their email with this.  Sorry had too, just felt in the mood to get a final stab at them.  call me a jerk or something.

Dear Customer Service,

I understand the privacy of your customers and I was kinda surprised to get the response that I got on first response.  So it came at no surprise to me that a follow up email correcting what was said before came into my inbox.

I am rather concerned though about how your company conducts business and could allow a active customer of yours to pay for their $3XX.XX or any amount water bill with someone else's debit card.  Do you have a verification process?  If not I suggest implementing one to prevent these kinds of transactions from happening.  These would be like asking for the billing address of the card which then would have shown up as being registered in the United States and that should have raised a few red flags.  Seeing as I don't buy anything from overseas or even Canada for that matter I feel my card # was compromised by a less than honest person that had access to my card for a recent purchase that I made and then was sold online on a stolen credit card forum which is common in Europe.

We both know that the relevant authorities are not about to waste their time on a small incident like this.  I hope that you would have been able to find information about this and make a note about it on the users acct that he used a stolen debit card #.  This would help the both of us and possibly stem this criminal from doing it again and could help your company become a leader in the UK in preventing ID theft.

Another thing that interested me and made me wonder how customer service is handled in the UK.  A 10 day response to a query seems to an awful lot?  Is this normal?  Why does it take your company 10 days to respond to a billing question?  Once again I urge you to review your customer service standards and try to improve on them as a 10 day waiting period for your customers is personally, horrible customer service and if you did that in the USA you would not be in business very long.  But maybe you guys run differently over there.
Logged

CHFI, C|EH, Security+, CPT
SephStorm
Sr. Member
****
Offline Offline

Posts: 416


View Profile WWW
« Reply #8 on: December 01, 2010, 08:17:18 AM »

you should have added: "respect my authoritah!"
Logged

Joshsevo
Sr. Member
****
Offline Offline

Posts: 263


View Profile
« Reply #9 on: December 01, 2010, 01:53:12 PM »

Do they have South Park over there or they just have Mr.Bean?  LOL. 

I was gonna throw in I am a Computer Forensics & Network Security analyst but since that is embleishing the truth by a few months, even though I do have a Forensics job but no certs I decided to leave it out.
Logged

CHFI, C|EH, Security+, CPT
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.152 seconds with 22 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.