Pune-based firm admits system breached in global ATM heist

Advertisement
By Reuters | Updated: 14 May 2013 18:15 IST
A Pune-based card processing company acknowledged on Monday that hackers breached its security to increase the limits on some pre-paid card accounts in a global ATM heist in December.

ElectraCard Services said no customer data was stolen from it and any tampering of ATM cards occurred elsewhere.

"To withdraw money from a pre-paid card, one needs an ATM card that has a magnetic strip, which has encoded data. You also need a PIN. The forensic report says that this data and PIN was not compromised at the ElectraCard data centre," said Ramesh Mengawade, chief executive officer of ElectraCard Services.

"However, in three or four accounts, there was a breach, where the limit of cash that can be withdrawn from a pre-paid card was increased," he said in an interview at his office in Pune.

Advertisement

U.S. prosecutors said on Thursday that hackers broke into two unnamed card processing companies, raising the balances and withdrawal limits on accounts that were then exploited in coordinated ATM withdrawals around the world that stole a combined $45 million from two Middle Eastern banks.

Advertisement

ElectraCard Services was the company that processed prepaid travel cards for National Bank of Ras Al Khaimah PSC (RAKBANK), according to a U.S. official and a bank employee who both spoke on condition of anonymity. RAKBANK suffered a $5 million coordinated heist at ATMs around the world on December 21 last year, the U.S. indictment said.

"What happened in December was an industry-wide attack," Mengawade said in his first interview since the case came to light last week. "There were pranks in India; there were pranks in the U.S., in Europe and at processors as well."

Advertisement

The company said the attack was external and no one inside the company was involved, and that it became aware of it within an hour and immediately notified clients and the police.

Another processing company, EnStage, which is incorporated in Cupertino, California, but has operations based in Bangalore, handled card payments for Bank of Muscat of Oman, sources have said. Bank of Muscat lost $40 million in a coordinated heist on February 19.

Advertisement

"Our customers were adversely affected by this sophisticated crime," EnStage CEO Govind Setlur said in a statement in the Times of India newspaper on Sunday.

ElectraCard was not associated with the February incident.

Outside investigator
ElectraCard hired U.S.-based Verizon Communications to investigate what happened in the December heist.

Verizon is one of the largest companies that certify that companies are in compliance with payment card industry standards set by Visa and MasterCard. It is also one of the biggest providers of incident response services to companies that are victims of cyber attacks.

"They are saying, yes, the fraudsters entered the system but they have not found any data because we don't store the data," said Ravi Sundaram, ElectraCard's head of strategy and corporate services.

"While somebody might have accessed my data in an unauthorised way, it still doesn't mean you can do an ATM withdrawal," he added.

The company has about 100 customers globally, all of them in financial services, and said it had not lost any in the wake of the December incident.

"This incident in no way impacts or troubles us in terms of our financials," Sundaram said. "We are well protected for that."

The head of the Pune police cyber crimes cell could not immediately confirm late on Monday whether a complaint had been filed by ElectraCard in the matter.

"It's an international gang and the U.S. is prosecuting them," Mengawade said.

After the incident, operations continued as usual, Mengawade said. "We put stop withdrawal instructions on only those cards which were showing such transactions," he said.

ElectraCard was delisted from a global industry standards body after the incident, but is still authorised to conduct transactions. Mengawade said he expects to be re-certified by June.

MasterCard bought a 12.5 percent stake in ElectraCard in 2010. MasterCard, the network under which the cards used in the heist were issued, has said its security was not compromised.

ElectraCard Services is a subsidiary of Opus Software Solutions, which is also headed by Mengawade.

© Thomson Reuters 2013

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: ElectraCard, Internet
Advertisement
Popular Mobile Brands
  1. These Samsung Phones Will Get Price Drops Ahead of Festive Season
  2. Biggest Offers on Smartphones During Amazon Great Indian Festival Sale
  3. OTT Releases This Week: Mahavatar Narsimha, The Bads of Bollywood, and More
  4. Samsung Galaxy A17 4G Goes Official With MediaTek Helio G99 SoC
  5. Vivo, iQOO Smartphones Likely to Switch to Origin OS in India
  6. Amazon Sale 2025: Top Deals on Logitech, Dell, HP, and More PC Accessories
  7. Flipkart Big Billion Days Sale: iPhone 17 Available With 10-Minute Delivery
  8. iQOO 15 is All Set to Launch in China Next Month
  9. Instamart Quick India Movement Sale 2025: Best Offers on Electronics
  1. Vivo, iQOO Smartphones Likely to Switch to Origin OS in India, Replacing Funtouch OS
  2. iPhone 18 Pro Models Tipped to Retain iPhone 17 Pro Design, Could Feature Transparent Back
  3. Tencent Says Sony 'Monopolising' Genre Conventions, Seeks Dismissal of Light of Motiram Lawsuit
  4. Samsung Galaxy A17 4G Launched With MediaTek Helio G99 SoC, 5,000mAh Battery: Price, Specifications
  5. Instamart Quick India Movement Sale 2025 Goes Live: Best Offers on Smartphones, Smartwatches and More
  6. Bitcoin Stabilises Near $116,900 as Altcoins Push Higher
  7. Mahavatar Narsimha Now Streaming on Netflix: Everything You Need to Know About This Animated Mythological Drama
  8. Nintendo Switch Online Adds First Third-Party Game Boy Advance Titles from Namco This September
  9. Big Billion Days Sale: Flipkart Minutes Promises Doorstep Delivery of iPhone 17, Galaxy S24 in 10 Minutes
  10. Amazon Sale 2025: Top Deals on Logitech, Dell, HP, and More PC Accessories
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.