$10 Gadget Claimed to Predict, Steal Credentials of American Express Cards

Advertisement
By Manish Singh | Updated: 26 November 2015 14:56 IST

A poor security implementation by American Express has made it possible for attackers to accurately predict the number of a user's next American Express credit card, and also figure out the expiration date of that card. A hacker has developed a device called MagSpoof, which is being sold for $10 (roughly Rs 650) and can let anyone exploit this vulnerability.

Samy Kamkar's MagSpoof can steal new credit card numbers as fast as American Express could generate them, he claims. The renowned hacker first observed this vulnerability when he lost his American Express card four months ago, and noticed a pattern in the credentials on his replacement American Express card.

"I pulled up the numbers to several other Amex cards I had, and then compared against more than 20 other Amex cards and replacements and found a global pattern that allows me to accurately predict American Express card numbers by knowing a full card number, even if already reported lost or stolen," he wrote in a blog post.

Advertisement

That isn't all. The watch-sized MagSpoof emits an electromagnetic field strong enough to hit a credit card reader's sensor from close proximity. It then sends a signal to trick point-of-sale readers into accepting payment from the device. The PoS devices, also known as chip-and-PIN readers and EVM, are designed to read cards that have a microchip with cryptographic encryption.

Advertisement

The security implications of getting the card "formula" out or a criminal getting their hands on the MagScoop device is that they can figure out the victim's next card number even before the victim receives it. This will allow the fraudster to use the victim's credentials to do transactions. Kamkar says that part of the reason he is exposing the vulnerability is to prove American Express wrong, which found his findings not a "major issue" when notified four months ago.

Kamkar said that he also studied the magnetic stripe on the back of payment cards to figure out how they work. He found a vulnerability that could allow him to manipulate the code the stripes sent to again fool PoS devices. He hasn't disclosed the vulnerability but has released the schematics and software for MagSpoof.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Here's When the Realme 16 Pro Series Will Launch in India
  2. Google's Pixel Upgrade Program Lets You Get the Latest Model Every Year
  3. Here's How Much The Redmi Note 15 5G Could Cost in India
  4. OTT Releases This Week: Thamma, Mrs Deshpande, Raat Akeli Hai The Bansal Murders, and More
  5. Oppo Pad Air 5 Launch Date Announced: See Expected Features
  6. Sony's Year-End Holiday Sale on PS5 Accessories, Games Kicks Off Next Week
  7. Oppo Reno 15 Pro, Reno 15 Pro Max Global Variants Surface on Geekbench
  8. YouTube Bans Popular Channels for Making Misleading AI-Generated Movie Trailers
  9. Instagram Will Now Restrict the Number of Hashtags You Can Use
  1. New FIFA Game to Launch on Netflix Games in Time for FIFA World Cup Next Year
  2. Honor Magic V6 Tipped to Launch With 7,200mAh Dual-Cell Battery, Snapdragon 8 Elite Gen 5 SoC
  3. YouTube Bans Popular Indian Channel for Making Misleading AI-Generated Movie Trailers
  4. OpenAI Updates AI Guidelines to Prioritise Teen Safety Over Other Goals
  5. Dominic and The Ladies Purse Out on OTT: Know Everything About Streaming, Plot, Cast, and More
  6. Sony Announces Year-End Holiday Sale in India on PS5 Accessories, Games
  7. Xiaomi 17 Ultra Battery, Charging Specifications and Colourways Tipped Ahead of Launch
  8. Redmi Note 15 5G Price in India, Storage Configurations Tipped Ahead of January 6 Launch
  9. Little Hearts Streaming Now on Netflix: Know Everything About Plot, Cast, and More
  10. Crypto Traders Remain Cautious Amidst Tight Liquidity and Mixed Global Cues
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.