{"id":6280,"date":"2022-08-18T12:00:00","date_gmt":"2022-08-18T09:00:00","guid":{"rendered":"https:\/\/blog.eset.ee\/?p=6280"},"modified":"2026-06-14T10:26:26","modified_gmt":"2026-06-14T07:26:26","slug":"5-ways-cybercriminals-steal-credit-card-details","status":"publish","type":"post","link":"https:\/\/blog.eset.ee\/et\/en\/2022\/08\/18\/5-ways-cybercriminals-steal-credit-card-details\/","title":{"rendered":"5 ways cybercriminals steal credit card details"},"content":{"rendered":"<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>The cybercrime underground is a well-oiled machine worth&nbsp;<a href=\"https:\/\/cybersecurityventures.com\/hackerpocalypse-cybercrime-report-2016\/#:~:text=If%20it%20were%20measured%20as,after%20the%20U.S.%20and%20China.\" target=\"_blank\" rel=\"noreferrer noopener\">trillions of dollars<\/a>&nbsp;annually. On dark websites hidden from law enforcers and most consumers, cybercriminals buy and sell huge quantities of stolen data as well as the hacking tools needed to obtain them. There are thought to be as many as&nbsp;<a href=\"https:\/\/resources.digitalshadows.com\/whitepapers-and-reports\/account-takeover-in-2022\" target=\"_blank\" rel=\"noreferrer noopener\">24 billion illegally obtained usernames and passwords<\/a>&nbsp;currently circulating on such sites, for example. Among the most sought-after is fresh card data, which is then bought in bulk by fraudsters to commit follow-up identity fraud.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>In countries that have implemented chip and PIN (also known as EMV) systems, it\u2019s challenging to turn this data into cloned cards. So most commonly it\u2019s used online in card-not-present (CNP) attacks. Fraudsters could use it to buy luxury items for onward sale, or potentially they could buy gift cards in bulk \u2013 another popular way to launder illicitly obtained funds. The scale of the market in these cards is difficult to estimate. But the administrators of the world\u2019s largest underground marketplace recently retired after&nbsp;<a href=\"https:\/\/www.bbc.co.uk\/news\/technology-59983950\" target=\"_blank\" rel=\"noreferrer noopener\">making an estimated US$358m.<\/a><\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>With that in mind, here are five of the most common ways hackers could get hold of your credit card data \u2013 and how to stop them:<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:heading \u2013><\/p>\n<h2>1. Phishing<\/h2>\n<p><!\u2013 \/wp:heading \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p><a href=\"https:\/\/www.eset.com\/uk\/types-of-cyber-threats\/phishing\/\" target=\"_blank\" rel=\"noreferrer noopener\">Phishing<\/a>&nbsp;is one of the most popular techniques for cybercriminals to steal data. At its simplest, it\u2019s a con trick in which the hacker masquerades as a legitimate entity (e.g., a bank, an e-commerce provider, or a tech firm) to trick you into divulging your personal details, or unwittingly&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/2020\/12\/23\/7-ways-malware-can-get-your-device\/\">downloading malware<\/a>. They often encourage users to click on a link or open an attachment. Sometimes doing so takes the user to a phishing page \u2013 where you\u2019ll be encouraged to enter personal and financial information. Phishing is&nbsp;<a href=\"https:\/\/docs.apwg.org\/reports\/apwg_trends_report_q1_2022.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">said to have hit<\/a>&nbsp;an all-time high in Q1 2022.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:image {\"id\":6284,\"sizeSlug\":\"full\",\"linkDestination\":\"none\"} \u2013><\/p>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"555\" height=\"583\" src=\"https:\/\/blog.eset.ee\/wp-content\/uploads\/2022\/08\/American-Express_phishing.png\" alt=\"\" class=\"wp-image-6284\" srcset=\"https:\/\/blog.eset.ee\/wp-content\/uploads\/2022\/08\/American-Express_phishing.png 555w, https:\/\/blog.eset.ee\/wp-content\/uploads\/2022\/08\/American-Express_phishing-122x128.png 122w\" sizes=\"auto, (max-width: 555px) 100vw, 555px\" \/><\/figure>\n<p><!\u2013 \/wp:image \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p><a  href=\"https:\/\/www.welivesecurity.com\/wp-content\/uploads\/2021\/10\/American-Express_phishing.png\" data-rel=\"lightbox-gallery-0\" data-rl_title=\"\" data-rl_caption=\"\" data-magnific_type=\"gallery\" title=\"\"><\/a><em>Example of a phishing email. For more details about this email, check out this article:&nbsp;<u><a href=\"https:\/\/www.welivesecurity.com\/2021\/10\/13\/phishing-how-be-one-got-away\/#:~:text=perfect%20their%20art.-,phresh%20phish,-Last%20week%2C%20I\" target=\"_blank\" rel=\"noreferrer noopener\">Don\u2019t get phished! How to be the one that got away<\/a>.<\/u><\/em><\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>These scams have evolved in recent years. Instead of an email, today you may receive a malicious text (SMS) from a hacker pretending to be a delivery company, a government agency, or another trusted organization. Scammers may even call you up, again pretending to be a trusted source, with the aim of obtaining your card details.&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/2021\/01\/22\/why-do-we-fall-sms-phishing-scams-so-easily\/\" target=\"_blank\" rel=\"noreferrer noopener\">SMS phishing<\/a>&nbsp;(smishing) more than doubled year-on-year in 2021, while&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/2021\/06\/14\/vishing-what-is-it-how-avoid-getting-scammed\/\" target=\"_blank\" rel=\"noreferrer noopener\">voice phishing<\/a>&nbsp;(vishing) also surged, according to&nbsp;<a href=\"https:\/\/www.infosecurity-magazine.com\/news\/smishing-and-vishing-2021\/\" target=\"_blank\" rel=\"noreferrer noopener\">one estimate<\/a>.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:heading \u2013><\/p>\n<h2>2. Malware<\/h2>\n<p><!\u2013 \/wp:heading \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>The cybercrime underground is a huge marketplace, not just for data but also malware. Over the years, different types of malicious code have been designed to steal information. Some record your keystrokes \u2013 for example, as you\u2019re typing in card details on an e-commerce or banking site. How do the bad guys get these tools on your machine?<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>Phishing emails or texts are a popular method. Malicious online ads are another. In other cases, they may compromise popular websites and wait for users to visit them. Drive-by-download malware of this sort installs as soon as you visit the compromised site. Info-stealing malware is also often hidden inside&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/2022\/05\/04\/3-most-dangerous-types-android-malware\/\" target=\"_blank\" rel=\"noreferrer noopener\">legitimate-looking but malicious mobile apps<\/a>.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:heading \u2013><\/p>\n<h2>3. Digital skimming<\/h2>\n<p><!\u2013 \/wp:heading \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>Sometimes hackers also&nbsp;<a href=\"https:\/\/www.eset.com\/uk\/about\/newsroom\/blog\/online-card-skimming\/\" target=\"_blank\" rel=\"noreferrer noopener\">install malware on the payment pages<\/a>&nbsp;of e-commerce sites. These are invisible to the user, but will skim your card details as they are entered. There\u2019s not much users can do to stay safe, aside from shopping only with big-name brands and websites, which are likely to be more secure. Detections of digital skimming (aka online card skimming)&nbsp;<a href=\"https:\/\/mediatrust.com\/blog\/2021-december-malware-trends-eskimming\/\" target=\"_blank\" rel=\"noreferrer noopener\">rose 150%<\/a>&nbsp;between May and November 2021.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:heading \u2013><\/p>\n<h2>4. Data breaches<\/h2>\n<p><!\u2013 \/wp:heading \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>Sometimes card details&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/2020\/10\/30\/5-scary-data-breaches-shook-world\/\">are stolen direct<\/a>&nbsp;from the companies you do business with. It could be a healthcare provider, an e-commerce store, or a travel company. This is a more cost-effective way to do things from the hackers\u2019 perspective, because in one attack they get access to a huge trove of data.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>On the other hand, with phishing campaigns, they have to steal from individuals one-by-one \u2013 although these attacks are usually automated. The bad news is that 2021 was a record year for data&nbsp;<a href=\"https:\/\/www.idtheftcenter.org\/post\/identity-theft-resource-center-2021-annual-data-breach-report-sets-new-record-for-number-of-compromises\/\">breaches in the US<\/a>.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:heading \u2013><\/p>\n<h2>5. Public Wi-Fi<\/h2>\n<p><!\u2013 \/wp:heading \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>When you\u2019re out and about it can be tempting to surf the web for free on&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/2015\/09\/02\/10-steps-staying-secure-public-wi-fi\/\">public Wi-Fi hotspots<\/a>&nbsp;\u2013 in airports, hotels, cafes, and other shared spaces. Even if you have to pay to join the network, it may not be safe if hackers have done the same. They can use this access to spy on your details as you enter them.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:heading \u2013><\/p>\n<h2>How to keep your credit card details safe<\/h2>\n<p><!\u2013 \/wp:heading \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>Fortunately, there are plenty of ways to mitigate the risk of your card data getting into the wrong hands. Consider the following as a good place to start:<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:list \u2013><\/p>\n<ul>\n<li>Be alert: never reply to, click on links in, or open attachments from unsolicited emails. They could be booby-trapped with malware. Or they could take you to legitimate-looking phishing pages where you\u2019ll be encouraged to enter your details.<\/li>\n<li>Don\u2019t divulge any details over the phone, even if the person at the other end sounds convincing. Ask where they\u2019re calling from and then call back that organization to check \u2013 although don\u2019t use any contact numbers they give you.<\/li>\n<li>Don\u2019t use the internet on public Wi-Fi, especially&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/2022\/06\/23\/virtual-private-networks-5-common-questions-vpns-answered\/\" target=\"_blank\" rel=\"noreferrer noopener\">without a virtual private network<\/a>. If you have to, don\u2019t do anything requiring you to input card details (e.g., online shopping).<\/li>\n<li>Don\u2019t save card details to online shopping or other sites, even though this helps to save time on future visits. This will reduce the chances of your card data being taken if that company is breached, or if your account is hijacked.<\/li>\n<li>Install anti-malware, including anti-phishing protection, from a reputable security vendor on all laptops and other devices<\/li>\n<li>Use&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/2019\/12\/13\/2fa-double-down-your-security\/\" target=\"_blank\" rel=\"noreferrer noopener\">two-factor authentication<\/a>&nbsp;on all sensitive accounts. This reduces the chances of hackers cracking them open with&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/2022\/06\/27\/5-ways-cybercriminals-steal-credit-card-details\/5%20ways%20hackers%20steal%20passwords%20(and%20how%20to%20stop%20them)\" target=\"_blank\" rel=\"noreferrer noopener\">stolen\/phished passwords<\/a>.<\/li>\n<li>Only download apps from legitimate marketplaces (Apple App Store, Google Play).<\/li>\n<li>If you\u2019re doing any shopping online, only do so on sites with HTTPS (it should display a padlock in the browser address bar next to the URL). This means there\u2019s less chance data can be intercepted.<\/li>\n<\/ul>\n<p><!\u2013 \/wp:list \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>Finally, it\u2019s good practice to keep an eye on all your bank and card accounts. If you spot any suspicious transactions, tell your bank\/card provider\u2019s fraud team immediately. Some apps now allow you to \u201cfreeze\u201d all spending on specific cards until you can ascertain whether there\u2019s been a security breach. There are plenty of ways for the bad guys to get our card details, but also lots we can do to keep them at arm\u2019s length.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The cybercrime underground is a well-oiled machine worth&nbsp;trillions of dollars&nbsp;annually. On dark websites hidden from law enforcers and most consumers, cybercriminals buy and sell huge quantities of stolen data as well as the hacking tools needed to obtain them. There are thought to be as many as&nbsp;24 billion illegally obtained usernames and passwords&nbsp;currently circulating on [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":6281,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[147],"tags":[],"class_list":["post-6280","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybercrime"],"acf":[],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/6280","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/comments?post=6280"}],"version-history":[{"count":0,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/6280\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media\/6281"}],"wp:attachment":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media?parent=6280"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/categories?post=6280"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/tags?post=6280"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}