ECONOMY & WORK
MONEY 101
NEWS
PERSONAL FINANCE
NET WORTH
About Us Contact Us Privacy Policy Terms of Use DMCA Opt-out of personalized ads
© Copyright 2023 Market Realist. Market Realist is a registered trademark. All Rights Reserved. People may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.
MARKETREALIST.COM / NEWS

Cyber-Criminals are Using 'BIN' Attacks for Card Fraud; Here's how to Stay Safe

Explore the covert world of cybersecurity as small businesses face an unprecedented surge in BIN attacks.
PUBLISHED JAN 11, 2024
Cover Image source: Pexels | Photo by Pixabay
Cover Image source: Pexels | Photo by Pixabay

Cybersecurity networks may be getting stronger, but cyber-criminals always seem to outpace that progress by coming up with more sophisticated tactics. The latest troubling trend to emerge in the space is the use of "BIN attacks" by cyber-criminals to target small businesses. This involves manipulating the Bank Identification Number (BIN) of credit cards, allowing fraudsters to test stolen card details through trial and error on unsuspecting e-commerce sites. This sophisticated cybercrime tactic not only poses financial threats to businesses but also leaves consumers questioning the security of their online transactions.

Pexels | Photo by Expect Best
Pexels | Photo by Expect Best

In 2023 alone, payment card fraud amounted to a staggering $577 million, which was a concerning 16.5% increase from the previous year. The Commonwealth Bank, among others, found itself at the center of this storm when a Melbourne wholesaler faced a barrage of 13,500 declined e-commerce transactions in just one month. What initially seemed like a clerical error soon turned out to be a sophisticated cybercrime technique that put both businesses and consumers on edge.

Cyber-criminals start by obtaining the first six digits of a credit card, known as the Bank Identification Number (BIN). With this information, they employ trial-and-error methods to decipher valid combinations of card numbers, expiration dates, and security codes. The stolen card details are then tested through small transactions that are hardly noticed, to determine their validity. Once confirmed, fraudsters either sell the compromised card numbers or use them for more larger fraudulent transactions.

Pexels | Photo by Pixabay
Pexels | Photo by Pixabay

Bob Barrow and John Goodall, both Commonwealth Bank account holders, found themselves victims of unauthorized transactions. Despite never using their cards online, they were shocked to discover transactions on their accounts, leaving them with doubts about the safety of their financial information, even though the bank reimbursed them.

Contrary to popular belief, credit card numbers are not as random or infinite as consumers might think. With 16 digits on a card, removing the six-digit BIN leaves just 10 digits that adhere to a specific pattern. The relatively limited possibilities make it feasible for cyber-criminals to use automated systems to rapidly guess valid combinations, posing a significant challenge for traditional security measures.

Pexels | Photo by Pixabay
Pexels | Photo by Pixabay

While the affected businesses call for tighter safety protocols, the responsibility is not solely on the banks. Financial institutions, often the victims themselves, issue cards but are not always the entities processing the transactions. The attacks highlight the need for a multi-layered defense, with businesses employing robust fraud protection tools and payment processors like Stripe and Square that prioritize online store security. This is needed since the aftermath of a BIN attack can be financially crippling for businesses.

Pexels | Photo by RDNE Stock project
Pexels | Photo by RDNE Stock project

As cyberattacks become more sophisticated, businesses must adapt to protect themselves and their customers. Popular platforms like Stripe and Square can serve as valuable allies in the ongoing battle against cyber threats, providing an additional layer of defense for businesses and their customers.

In an era where convenience and speed define online transactions, the dark underbelly of cybercrime poses a persistent challenge. BIN attacks, with their focus on small businesses, remind us of the fragility of digital financial ecosystems. As businesses and financial institutions work to bolster their defenses, consumers are encouraged to remain vigilant and report any suspicious transactions promptly. The delicate balance between ease of use and security continues to be a tightrope walk in the digital age, with each innovation met by an equally cunning cyber threat.

MORE ON MARKET REALIST
While the host fumbled the card, it had just enough for Brenda to win a brand new car
1 day ago
The nonpartisan fiscal watchdog revised its estimates to add $2 trillion to its earlier projection.
1 day ago
Chevron president Andy Walz urged the state's regulators to review their climate policy.
1 day ago
Harvey looked like he had enough as yet another question popped up, targeting him on the show.
1 day ago
Frito-Lay has recalled certain bags of its popular Miss Vickie's Dill Pickle Potato Chips
1 day ago
Americans are paying 26 cents more for gas than a week ago.
2 days ago
Harvey was left holding his stomach after almost every answer the Hunter family gave.
2 days ago
The firm's chief global equities strategist, Peter Oppenheimer, has warned that a correction is imminent.
3 days ago
The suit alleged Tinder charged older users more for its Gold and Platinum subscriptions
3 days ago
The Yoyo Gummy candies are part of an ongoing recall across 14 states over unallowed food dye.
3 days ago
The two progressives estimate the tax would bring in $4.4 trillion over the next decade.
5 days ago
Hearing the answer, Harvey knew the contestant would need god by his side to save his marriage.
5 days ago
After painfully losing out by 5 points the previous night, the Baccus family made a comeback
6 days ago
Harvey's anecdotes made it clear that he had been through some steamy situations.
6 days ago
Michael Green isn't worried about AI stocks, as a passive investment bubble is a "more salient" risk
6 days ago
The AI assistant app seems to have benefitted from the headlines that emerged after Trump's rant.
6 days ago
AT&T, Verizon Wireless, and T-Mobile have their own spam blocking tools for their subscribers.
6 days ago
The newly introduced Trump accounts have the same tax advantages as IRAs.
Feb 27, 2026
While the IMF warned the current administration's policies could make deficits worse.
Feb 27, 2026
Fans couldn't believe how a contestant failed to secure just 31 points out of the 200 that his partner had scored.
Feb 27, 2026